<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:cc="http://cyber.law.harvard.edu/rss/creativeCommonsRssModule.html">
    <channel>
        <title><![CDATA[Stories by Admiral Cloudberg on Medium]]></title>
        <description><![CDATA[Stories by Admiral Cloudberg on Medium]]></description>
        <link>https://medium.com/@admiralcloudberg?source=rss-e119a26506e3------2</link>
        <image>
            <url>https://cdn-images-1.medium.com/fit/c/150/150/1*i5QbsmB2XH5E_XF-tLxaUg.png</url>
            <title>Stories by Admiral Cloudberg on Medium</title>
            <link>https://medium.com/@admiralcloudberg?source=rss-e119a26506e3------2</link>
        </image>
        <generator>Medium</generator>
        <lastBuildDate>Sun, 19 Jul 2026 21:01:58 GMT</lastBuildDate>
        <atom:link href="https://medium.com/@admiralcloudberg/feed" rel="self" type="application/rss+xml"/>
        <webMaster><![CDATA[yourfriends@medium.com]]></webMaster>
        <atom:link href="http://medium.superfeedr.com" rel="hub"/>
        <item>
            <title><![CDATA[Progress Update: New article coming soon, and a teaser]]></title>
            <link>https://admiralcloudberg.medium.com/progress-update-new-article-coming-soon-and-a-teaser-24f9093cbc40?source=rss-e119a26506e3------2</link>
            <guid isPermaLink="false">https://medium.com/p/24f9093cbc40</guid>
            <dc:creator><![CDATA[Admiral Cloudberg]]></dc:creator>
            <pubDate>Sat, 18 Jul 2026 19:10:15 GMT</pubDate>
            <atom:updated>2026-07-18T19:10:15.827Z</atom:updated>
            <content:encoded><![CDATA[<p>Hello readers! It’s been a while! Over the past several months, I worry that many of you lost hope that you would see more content from me; I know quite a few understandably stopped supporting my <a href="https://www.patreon.com/Admiral_Cloudberg">Patreon</a>. But it turns out that for much of that time, I’ve actually been hard at work on something so big that I’m not even going to know what to do with myself when it’s done.</p><p>First, I need to explain some things that have been happening in my life. During the first three months of 2026 I went through what might have been some of the worst depression of my adult life. It wasn’t that bad compared to what many people have experienced but everything is relative, all pain is valid, etc., etc. I managed to produce the Hawker stall test article during that period, but then the final report on the Potomac River midair collision came out, and I knew I had to do it next. But in my depressed state, I couldn’t find the motivation to work on a project that large, with a 400-page final report forming just the tip of a massive iceberg that includes 18,000 pages of NTSB evidence and thousands of news articles, in addition to a scope so wide it was hard to know where to even begin. In truth I didn’t even start working on the article until late April, after coming back from a 10-day car camping trip in the Southwest US intended to reset my brain and my life, followed by a week lost to some kind of Victorian wasting disease (read: the flu probably).</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*gwfj335SCtWf2an5tHfMTA.jpeg" /><figcaption>Me in the mostly abandoned town of Cisco, Utah during the road trip. Yes I’m really that tiny. Photo by my friend Younghyun.</figcaption></figure><p>However, since late April, I’ve been working on this article almost nonstop. That’s 3 full months now, for those keeping track. And now, as we approach the end of July, with headlines no doubt reporting my almost certain death, I’m happy to report that my long-awaited article on the Potomac midair will, with 100% certainty, release before the end of the month and possibly as soon as next weekend, July 25/26.</p><p>So, in the interest of building some hype for that, I want to talk about the article and my process of researching and writing it, and offer a teaser.</p><p>This article is my longest ever by a margin of approximately two thirds. By that I mean my previous longest article, Aeroflot 1492, which clocked in at over 30,000 words, will fall 20,000 words short of this one. I’m not quite done drafting so I don’t have an exact word count but based on what I’ve already written and what I have left in my outline I expect 50,000 words will be about where it ends up. That corresponds to over 90 pages of 12-point, single-spaced text in a Microsoft Word document with standard margins.</p><p>At that point, one might fairly question whether this is an article at all, as opposed to a book. But it’s not a book; if I were writing a book I would have structured it rather differently, and it would have been much, much longer. I haven’t done things that I would do if I were writing a book, such as sitting down for interviews with people who were involved in order to hear from them myself, instead of just reading the transcripts of their interviews in the NTSB evidence docket. Therefore I think it would be more accurate to characterize this as a long-form essay.</p><p>One might question the point of writing an essay this long, when one of the advantages (albeit far from the only advantage) of my articles is that readers can learn what happened in reasonable detail without having to sit down and read an entire accident report. But, as a good friend said to me the other day, if people want a summary, they can read Wikipedia. I always strive to give a heavily contextualized, engaging analysis of the events in a way that allows the reader to truly understand what happened, and I write however many words I feel are necessary to accomplish that.</p><p>How does one write an essay that long? Well, here’s a breakdown.</p><p>I always start by reading the accident report while taking detailed notes. I create a bulleted list organized by section so I can find the corresponding text in the report more easily later. I write notes in complete sentences and without using much shorthand because I find it reduces mistakes and commits the content to memory more effectively.</p><p>After taking notes on the whole NTSB report, I check out other major sources, which can include articles or documents linked in the Wikipedia references section, or in this case, ones I had been collecting in a “links document,” like a crow collecting shiny things, ever since the accident occurred in January 2025. Those produced more bulleted notes. From there, I dived into the NTSB evidence docket, downloading dozens of documents that I thought might contain useful information and scanning them for relevant details, producing yet more notes. By this point, a picture of the accident and the themes of the article would have been coming together in my head, which led me to start formulating questions that I couldn’t have considered earlier in the process. And that led me to hunt down more documents in an effort to answer them.</p><p>My research included, among many other things, watching nearly 27 hours of NTSB public hearing footage, where I wrote down every relevant snippet of information with the approximate time stamp so I could find it again later. I also spent several days combing through a giant Excel spreadsheet of traffic count data from DCA in the week before the accident and comparing it to slot control statutes, a big table of slot awards, and FAA arrival rate limits, all in an effort to understand the NTSB’s conclusion that the airport was suffering from excessive traffic.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2TQe19O9SxW7zoCFx4arjg.png" /><figcaption>If you’re wondering what an Excel spreadsheet of traffic count data looks like, it looks like this.</figcaption></figure><p>By the time I was done, I had a Word document containing 62 pages of notes (again, 12 point font, single spaced, standard margins).</p><p>I then sat down and drafted an outline of the essay, with a planned nine chapters and dozens of subheadings intended to cover all the major topics in the order I felt made the most sense. I then assigned each chapter a color, and I went through the notes highlighting each bullet point in the color corresponding to the chapter where I felt that piece of information was most likely to be mentioned. This helps me quickly find the notes I need, when I need them. By the time I was done, the final product looked like this:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pR7R0RGCLjyEpFCWqTmhOw.png" /></figure><p>To finish research and note-taking took me just under two months. At that point, around mid-June, I transitioned to actually writing the essay.</p><p>This was not an especially quick process, especially at first. When I start putting words onto the page, it always raises new questions that prompt new research, and as a result the notes document actually increased by about 8 pages to its final length of 62 after I had already started writing. I’m also following a strict in-line citation policy, where everything I say needs to be tied to a specific line in a specific source, so whenever I pull something out of my notes I have to find the corresponding line in the source and cite it. As a part of this process I’ve been building up a bibliography, which currently stands at 42 sources and could push 50 by the time the essay is done.</p><p>It would also, however, be dishonest of me not to mention that I watched every single World Cup match (except for two that I missed), so I was only writing in between matches. It only comes around once every four years; what are you gonna do, sue me?</p><p>Ever since I started, I’ve written an average of probably about 1,500 words per day, although that number has been increasing lately as the finish line approaches. After I reach the end of my draft, I’m going to go back and closely read the whole thing, editing syntax for clarity; putting in any missing citations; removing any details that don’t feel so important in hindsight; and adding any that in hindsight appear to be missing. After that, I’m going to send the draft to a couple other subject matter experts for final review, and then I’ll format it for upload here on Medium. Due to its length, I’ll also be making a downloadable PDF version available.</p><p>The essay covers a very wide scope, from the politics of slot controls to the safety culture at the DCA control tower to the decline in experience among military aviators. It contains eye-opening details from the evidence docket that have not been widely reported.</p><p>As a teaser while you wait for the final product, here’s the introduction to the essay:</p><blockquote>It was a clear and mild evening in America’s capital, warm enough to melt the concreted banks of nearly month-old snow and send the last frigid fragments of ice fleeing down the dark waters of the Potomac. Above the black expanse of the river, aircraft approaching Ronald Reagan Washington National Airport were strung across the sky like a chain of Christmas lights, lining up for the last big push before traffic trailed off into the night. The clock read 8:47 p.m.</blockquote><blockquote>By January 2025, it had been nearly 16 years since the last time a major disaster befell a US airline. Countless aviation professionals had begun, developed, and even ended their careers without ever seeing one. On an intellectual level, all understood the statistical certainty that that record would one day end, and that the time and place of its ending, whether it be today or 10 years from now, in New York or Alaska, could not be predicted. And when it finally did happen, at 8:47 p.m. on the 29th of January 2025, at a height of 278 feet above the Potomac River in Washington D.C., it was difficult to comprehend that that day had in fact been today, and that an unprecedented period of safety had suddenly been consigned to the past. But for many who flew or worked in that crowded, hectic airspace, the fact that it ended at National Airport was not a surprise: their sentiment tinged by hindsight, they collectively said, “If it had to be anywhere, it would have been DCA.”</blockquote><blockquote>How could it be that such a tragedy retroactively struck so many as inevitable? The fact is that some people did see it, or something like it, coming from a long way off. And the story of how it was nevertheless allowed to happen is one that spans decades, disciplines, and institutions, from the cockpits of the two downed aircraft to the halls of Congress itself. It was born out of a web of interlocking interests and policies that formed a seemingly intractable milieu of dysfunction, in which those who had the whole picture lacked the power to change it, and those who did have the power to effect change did not see the whole picture.</blockquote><blockquote>Now, lubricated by the shock of disaster, the gears of bureaucracy have begun to turn, advancing safety improvements that will help make American airspace safer. But even as I write this, the same forces that created the conditions for that disaster remain at work, steadily pushing us into the jaws of the next one.</blockquote><p>◊◊◊</p><p>See you in a week or two! And don’t forget to <a href="https://www.patreon.com/Admiral_Cloudberg">support me on Patreon.</a></p><p>— Kyra</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=24f9093cbc40" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[The Most Dangerous Line: Behind the Hawker stall test crashes]]></title>
            <link>https://admiralcloudberg.medium.com/the-most-dangerous-line-behind-the-hawker-stall-test-crashes-85f1c79f1e0d?source=rss-e119a26506e3------2</link>
            <guid isPermaLink="false">https://medium.com/p/85f1c79f1e0d</guid>
            <category><![CDATA[aviation]]></category>
            <category><![CDATA[travel]]></category>
            <category><![CDATA[flying]]></category>
            <category><![CDATA[technology]]></category>
            <dc:creator><![CDATA[Admiral Cloudberg]]></dc:creator>
            <pubDate>Wed, 18 Feb 2026 20:12:02 GMT</pubDate>
            <atom:updated>2026-03-24T03:54:04.664Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*X28Sd12CsG8ESDVv.jpg" /><figcaption>The charred remains of Hawker 900XP N900VA where they came to rest in the high desert of Utah following a failed stall test. (NTSB)</figcaption></figure><p>On the 16th of October 2025, motorists on Interstate 69 near Lansing, Michigan caught sight of a Hawker 800XP business jet falling like a leaf from the late afternoon sky, followed moments later by an ominous plume of smoke. In a nearby forest, three crewmembers lay dead — the latest victims in a string of crashes and near misses connected to post-maintenance stall tests involving the popular corporate jet family. In fact, just a year and a half earlier, two more pilots lost their lives under near-identical circumstances while performing a post-maintenance stall test on a Hawker 900XP near the Colorado-Utah border. Many others have come close, only to escape, shaken but alive. These tragedies and close calls have turned stall tests in Hawker jets into a hot topic within the aviation community, posing questions about how they should be done, by whom, when, and why. The fact is that these accidents are not occurring on other business jets of similar design, and the reasons why are not made readily apparent simply by reading official reports. The National Transportation Safety Board has recommended stricter pilot qualifications for post-maintenance stall tests, but do the proposed changes go far enough? Do they tackle the real root causes of the test flights’ tragic record? What follows is my best attempt to address what is happening, why it’s happening to Hawkers, and what insiders think ought to be done about it.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*OFJ51G5U2N0wYkLv.jpg" /><figcaption>A prototype de Havilland DH 125 on display in Farnborough, England in 1962. (Wikimedia user TSRL)</figcaption></figure><p>In 1961, British aircraft manufacturer de Havilland began designing what would prove to be the United Kingdom’s first business jet, a twin rear-engine, center-aisle model designed to carry 8 to 14 passengers on trips up to 3,000 kilometers and at altitudes up to 41,000 feet. As far as business jets go, its layout, appearance, and mission are unremarkable, and the model was not necessarily revolutionary even at the time of its inception, but it was conventional, it was reliable, and it met the demands of its customers. It would go on to become Britain’s best-selling commercial jet.</p><p>By the time the type entered production in 1963, de Havilland had been absorbed into Hawker Siddeley, and the new business jet was marketed as the Hawker Siddeley 125 until that company was in turn consolidated into British Aerospace, or BAe, in 1977, after which it became known as the BAe 125. Production of new and updated variants continued into the 1990s, until the type certificate was sold to US aerospace defense contractor Raytheon in 1994. Raytheon continued production in the United States, marketing the base model as the Hawker 800. A further change of ownership then occurred in 2007, when Raytheon spun off its Hawker and Beechcraft divisions into Hawker-Beechcraft, which in turn produced a wave of new variants, including the Hawker 800XP, Hawker 750, Hawker 900XP, and more. However, Hawker-Beechcraft went bankrupt in 2012, and in 2013 the last Hawker rolled off the assembly line, ending a 50-year production run that saw 1,720 aircraft built.</p><p>Nevertheless, many Hawkers and some BAe-125s of all vintages and variants remain in service today, with ongoing support provided since 2013 by Textron Aviation, the new owner of the restructured Beechcraft Corporation, which still holds the type certificate. Over its lifetime, the type certificate has been held by either 6 or 7 different owners, depending on the method of counting — an unusually high number of transfers. The significance of this fact is debatable, and debate it I will, later in this article.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*P_ZL_XY5ALE00zIe.jpg" /><figcaption>N900VA, the aircraft involved in the Grand Junction accident. (Brad Ice)</figcaption></figure><p>In the meantime, though, let’s bring our focus to the 7th of February 2024, at Grand Junction Regional Airport in Grand Junction, Colorado.</p><p>Grand Junction is the largest city on Colorado’s western slope, home to about 65,000 people, as well as a maintenance facility called West Star Aviation, which was approved to maintain Hawker jets. At the facility that day was a Hawker 900XP, registration N900VA, owned by Vici Aviation and operated by Clay Lacy Aviation, a large aircraft-for-hire company based out of Van Nuys, California with a fleet of over 100 business jets.</p><p>N900VA had arrived at Grand Junction on December 20, 2023 to undergo scheduled heavy maintenance and inspections, similar to what’s known in the airline world as a C-check. This work involved partial disassembly of aircraft components, including portions of the wings, in order to inspect for damage, cracks, and corrosion.</p><p>On the third of January, 2024, technicians removed the wing leading edge panels in order to examine the panels themselves and the underlying wing structure, a task that must be completed every four years. This process involved removing the Hawker’s anti-icing panels.</p><p>The wing anti-icing system on the Hawker is relatively unusual among transport category jet aircraft. Most jets prevent ice from building up on the wing leading edge by pumping hot bleed air from the engines into the wing, but Hawkers instead have a system that secretes anti-icing fluid through a micro-porous plastic sheet, followed by a porous titanium skin, whereupon the fluid is blown back across the upper wing surface by the oncoming airstream. This system, called the TKS, is built into the wing leading edge panels, necessitating disconnection of fluid lines and other system elements in order to accomplish the aforementioned structural inspections.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*k_n7McPQnGGSSinW9-2Wkg.png" /><figcaption>Overview of the airframe ice protection system on the Hawker, including the location of fluid supply lines inside the leading edge. (Textron Aviation)</figcaption></figure><p>On January 4, the technicians removed and cleaned the TKS panels, discovered a leaky fluid line, and re-sealed it. An inspector signed off on the work on January 11, confirming that it met the standards set forth in the maintenance manual. The leading edge and TKS panels were subsequently reinstalled on January 18, during which another leaky valve was re-sealed and a missing screw was replaced. A further inspection was then carried out, again finding no discrepancies. Two more final structural inspections were then accomplished on the 30th of January, following completion of the work.</p><p>This work was performed in accordance with the structural repair manual, or SRM, section 57–41–00, “WINGS LEADING EDGE AND LEADING EDGE DEVICES WING LEADING EDGE GENERAL REPAIR,” which also stated the following:</p><p><em>“In accordance with the Flight Manual procedures the airplane must be test flown by a pilot familiar with the stall identification system and stall characteristics of the 750, 800, 800XP, 850XP, and 900XP series if:</em></p><p>- <em>The leading edge assembly was removed as a whole for any reason</em></p><p>- <em>Two or more TKS [de-icing] wing distribution panels on one side are removed or installed.”</em></p><p>Later in this article, I’m going to dive into where this provision came from, what it means in a strict legal sense, and what its authors might have intended for it to mean. For now, it suffices to say that the provision was extremely ambiguous, but most Hawker operators, pilots, and mechanics didn’t really appreciate that this was the case. Instead, the common interpretation was that, in the event that one of the two listed maintenance tasks had been performed, the aircraft would undergo a “stall test” to confirm “acceptable” stall behavior, and that this test must be flown by a pilot who has performed such a test in the past. So for the moment, let’s take that interpretation at face value, even though I’m going to tear it to smithereens later.</p><p>The stated reason for this post-maintenance test flight was to confirm that the maintenance work on the leading edge had not altered the jet’s stall characteristics.</p><p>For my lay readers who may not be familiar with the concept, a stall occurs when the angle of attack, approximately equal to the pitch angle minus the flight path angle, becomes too high to sustain normal airflow over the wings. As the stall approaches, lift increases, until a certain critical angle of attack, where the airflow begins to “separate” from the upper wing surface, generating a region of turbulent air above and behind the wing. At this point — the moment of the stall — lift abruptly decreases, and the plane rather suddenly begins to fall rather than fly.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/336/0*QmEAcftWqW-OXoDm.jpg" /><figcaption>A very basic visual explanation of how a wing stalls at high angle of attack. (Jonathan Stern)</figcaption></figure><p>Most aircraft, and especially high performance aircraft, are susceptible to airflow disruptions caused by very small surface imperfections, particularly on the leading edges. These imperfections can be ice crystals, chipped paint, dings and dents, splatters of sealant, you name it — but in all cases the effect is to assist the process of airflow separation, causing this separation to occur more readily and at a lower angle of attack. This is why aircraft have anti-icing systems, and it’s also sometimes imagined to be why Hawker aircraft must undergo a stall test following maintenance work on the leading edges, but this is not actually the case. The leading edges undergo multiple redundant inspections prior to release in order to identify any imperfections or contaminants, and by the time the stall test takes place, there should be none present.</p><p>In reality, the reason that a stall test is required after removing the leading edge is because a pair of obscure components called the stall triggers, also called stall spoilers, are built into the anti-icing panel.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/950/1*kZmIIBHTrv0wnCpKy-f9_Q.png" /><figcaption>Excerpt from the earlier diagram highlighting the location of the stall triggers. (Textron Aviation)</figcaption></figure><p>The stall triggers are small mechanical flaps that disrupt airflow at the moment of the stall, not to prevent or delay it, but to cause it to develop in the correct sequence. Like all high performance jets, the Hawker has wings that “sweep” rearward toward the tips, which is also where the ailerons are located. One characteristic of all swept wing airfoils, including the Hawker’s, is that they naturally want to stall tip-first. But if airflow separation begins at the wingtips, then the loss of smooth airflow over the ailerons will render the pilot unable to control the aircraft’s roll axis, leading to a potentially quite severe roll excursion before the stall fully develops. In order to rectify this behavior, the Hawker is equipped with stall triggers to ensure that when the angle of attack approaches the stall threshold, the stall triggers disrupt airflow over the wing roots before separation occurs at the wingtips, ensuring that the pilots retain roll control all the way into the stall.</p><p>Because every airplane is imperceptibly different (no matter how hard the manufacturer strives for uniformity), the stall triggers are adjustable in order to ensure that they deploy at exactly the right time during the stall sequence on each individual aircraft. Too early, and they will stall the wing roots before the crew has received adequate warning; too late, and the stall could begin at the wingtips before the triggers engage, leading to a loss of roll control. Therefore, before each Hawker was delivered, factory test pilots flew it up to the stall threshold in order to check whether the stall triggers kicked in at the right time, and if they did not, then engineers adjusted the position of the triggers in the required direction, and the test was performed again. These steps were repeated until the setting was correct.</p><p>Once the stall triggers had been set at the factory, there was no reason for them to ever be adjusted again. However, because the stall triggers are built into the same leading edge section as the TKS anti-icing system, removing the anti-ice panels also disconnects the stall triggers. During this process, the triggers could be accidentally moved, or the datum against which they were originally calibrated could shift imperceptibly, causing the trigger’s precise timing to be thrown out of whack. None of the maintenance or repair manuals contained guidance that would fix this issue. In fact, if the stall triggers were accidentally moved, the maintenance manual instructed technicians to return them to the “standard” setting, which is where they were installed when the plane rolled off the assembly line, before the checks and adjustments carried out by the factory test pilots. If the mechanics followed this guidance, then the stall tests would have to be performed again so that the correct stall trigger adjustment could be rediscovered. Because of these issues, any work involving removal of the TKS panels currently requires a post-maintenance stall test, regardless of whether the technicians report touching the stall triggers.</p><p>◊◊◊</p><p>The earlier mentioned SRM section 57–41–00 refers readers to section V, subsection 1 of the Pilot’s Operating Manual (POM), which provides a procedure for testing the stall characteristics of the aircraft. This subsection states the following:</p><p>- The stall test must be conducted at an altitude between 10,000 and 18,000 feet, so as to ensure adequate terrain clearance, but without entering the high altitude regime where there is less performance margin.</p><p>- The stall test must be conducted in daylight visual conditions with a good visible horizon.</p><p>- The airplane should be configured with the autopilot disengaged, ventral fuel tank empty, wings free of ice, and trim set to 1.4 times the stall warning speed (so that this is the speed the aircraft is balanced at, and will seek to return to).</p><p>- The pilot should slow the plane in wings-level flight at a rate of up to 1 knot per second, avoiding rapid control movements, especially after the stick shaker stall warning activates.</p><p>- The test should be carried out up to the stick pusher activation, at which point a recovery should be made. Any roll should be corrected using the ailerons.</p><p>Here I need to go over the stall warning and protection systems on the Hawker, which include the stick shaker and the stick pusher.</p><p>The stick shaker is a stall warning that begins shaking the pilots’ control columns when the angle of attack is getting too close to the stall threshold. Pilots are trained to react to the stick shaker by immediately reducing pitch and increasing thrust to prevent the stall from occurring, but during a stall test they must ignore this training.</p><p>The stick pusher is a feature of all T-tail aircraft susceptible to “deep stall,” which occurs when the region of turbulent airflow at high angles of attack blanks out the elevators on the tail, causing a loss of pitch control that prevents recovery from the stall. This type of stall behavior is not certifiable, so airworthiness regulations require the installation of a stick pusher that physically pushes the control columns forward to reduce the angle of attack just before reaching the stall point. In conventional aircraft like the Hawker it is possible for the pilot to override the stick pusher, in case it activates erroneously.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/589/1*MFfHIOwQn6kAHq2OKtDdJw.png" /><figcaption>Aerodynamic diagram of a statically stable deep stall; i.e. elevators blanked out, leading to a loss of pitch control and impossibility of reducing the AOA. Fun fact: during production test flights, Hawkers were fitted with drogue chutes that could be deployed to force the nose down in order to recover from a deep stall. (Image: Duc Nguyen et al 2023)</figcaption></figure><p>I must note that in one-G flight at a constant altitude, there is a predictable relationship between airspeed and angle of attack, because both variables are on the same side of the lift equation. Assuming constant lift (required to maintain constant altitude at constant weight), a decrease in airspeed must be accompanied by a proportional increase in angle of attack, or else lift would decrease and the aircraft would descend. Therefore, while the stall point is solely dependent on angle of attack, not airspeed, the relationship is predictable enough that for handling purposes, pilots usually do think in terms of “stall speed” and “stick shaker speed” rather than stall AOA. For that reason, it is said that the Hawker’s stick shaker activates about 7–9% above the stall speed, while the stick pusher activates about 4 knots above the stall speed.</p><p>Those systems are programmed based on predetermined AOA values, so if the aircraft begins to stall earlier than anticipated, either due to contamination of the wing surface or an improperly adjusted stall trigger, then the above airspeed margins may not be met, which would be considered a stall test failure condition. In such a case, the pilots would perceive the discrepancy as a stall that begins at too high an airspeed, when in fact it occurs at an angle of attack that is too low.</p><p>The stall test guidance in the POM refers pilots to an Aircraft Flight Manual (AFM) table of stall speed figures for different weights and configurations, presumably in order to check that the actual aircraft performance matches the figures, although the POM does not explicitly state this.</p><p>Additionally, the stall test guidance includes a brief description of some aircraft behaviors that would be considered “unacceptable” during a stall test. These behaviors include a roll that cannot be contained to 20 degrees using the ailerons, as well as “aileron snatch” and “overbalanced ailerons.” Neither of these terms is defined in the POM, although they are understood to be possible side effects of airflow separation at the wingtips instead of the wing roots. The POM advises that if any of these phenomena should be encountered, recovery can be accomplished by pitching down to reduce the angle of attack and exit the stall regime.</p><p>Finally, the stall test guidance ends with a caution: <em>“Pilots conducting stall checks should have prior experience in performing stalls in the Hawker and must be prepared for unacceptable stall behavior at any point leading up to and throughout the maneuver.” </em>This caution dovetails with the SRM requirement that the stall test pilot be “familiar with the stall characteristics” of the Hawker series. As I stated earlier, companies interpreted this provision to mean that the pilot should have performed at least one Hawker stall test in the past. There was no clear definition of what constituted “preparedness for unacceptable stall behavior,” nor was there any requirement for special training beyond what would be learned on-the-job during a previous stall test.</p><p>As a result, most operators rostered regular line pilots to perform the stall tests, of which the captain was required to have performed a stall test before, with no such requirement for the first officer. The wisdom of allowing line pilots to perform the tests without special training had been questioned by some insiders for years, but as N900VA neared its test flight, those questions had so far fallen mostly upon deaf ears.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*eu7oEwXpWLm_yYqTNPRgZQ.png" /><figcaption>Basic map of N900VA’s planned flight. (Own work, map by Google)</figcaption></figure><p>Clay Lacy Aviation’s plan for N900VA was for two regular line pilots to fly it to Tacoma Narrows Airport in Gig Harbor, Washington, performing the stall tests while <em>en route,</em> with a return to Grand Junction in the event that the test failed.</p><p>In command was a 65-year-old captain with over 15,000 flying hours across an extensive career, including 2,249 hours in the Hawker 900. The second-in-command was a 58-year-old first officer with over 8,000 total hours, but just 70 on the Hawker, to which he had recently transferred. Unlike my typical practice, I will not be mentioning the names of either pilot because this article includes biographical information that has not been widely reported outside of NTSB documents. Instead, I’ll be referring to them as the PIC (pilot in command) and SIC (second in command), respectively.</p><p>The PIC had an enviable resumé, with type ratings in the Boeing 727, 737, 757, 767, 777, and 787; Lockheed L-1011 Tristar; Bombardier CL-65 (Challenger); Fairchild/Swearingen SA-227 Metroliner, and Hawker HS-125/800XP/900XP. He was also an instructor on four Boeing models; an FAA check airman; lead technical pilot for Boeing’s Extended Envelope Training Program, including full stall recognition and recovery modules; and an Upset Prevention and Recovery Training program development pilot for five Boeing models. There was no doubt that he was an experienced, competent, and capable pilot, exactly the kind you would seemingly want in the left seat during a nonstandard maneuver. All the instructors at the facility where he received his most recent recurrent simulator training in the Hawker also described him in excellent terms, and he breezed through the training with no problems whatsoever. However, he had only performed one previous Hawker stall test, more than four years earlier, in which he was the SIC.</p><p>The SIC, although not by any means inexperienced, was new to the Hawker and did not have the kind of aviation pedigree that the PIC did. He had never previously performed a stall test, but that was unsurprising given his low number of hours on type.</p><p>It has been pointed out in reporting on this accident that the SIC’s simulator training on the Hawker had not gone smoothly. According to NTSB interviews with his instructors, during his type rating course, he failed a simulator session after entering an “undesired aircraft state” — a condition in which the real aircraft would have been damaged or destroyed — five separate times. After this disastrous session, the instructor sat down with him to debrief, and the SIC explained that his brother had terminal cancer and his son had recently passed away, and that day had been particularly hard for him. He was subsequently sent to a different instructor to redo the simulator session, and he was able to pass with no problems.</p><p>In my opinion, this training history was clearly not representative of the SIC’s actual skill level. Sometimes pilots just have a bad day, especially when faced with such difficult life circumstances, and it’s impossible to hold those circumstances against him. The interviews and reports included in the National Transportation Safety Board’s evidence docket don’t indicate that he had a history of training difficulties outside of this period, and I would tend to reject any assertion that the failure made him a riskier choice for the stall test than any other SIC of his experience level. As for whether anyone with 70 hours in the Hawker should be chosen as SIC for a stall test, I’ll examine that question later, and the answer might not be what you think.</p><p>In any case, on February 7, the two pilots met the airplane at West Star Aviation’s facility at Grand Junction Airport, and performed a thorough pre-flight inspection. They did not find any contamination of the wing leading edges, and the mechanics had not reported moving or touching the stall triggers in any way, so there was no particular reason why this aircraft should have been likely to fail a stall test. Nevertheless, the test was required.</p><p>The pilots were well aware that the weather that day was far from optimal for a test flight. Dense clouds blanketed Colorado’s western slope, with tops from 15,000 to 17,500 feet, and at Grand Junction Airport witnesses reported that sleet was falling as the pilots prepared the aircraft for flight. The National Weather Service had also issued an AIRMET notice warning air crews of possible icing conditions between 6,500 and 20,000 feet, while pilots in the area confirmed the existence of icing conditions between 7,800 and 15,300 feet above sea level. Even so, the pilots planned to proceed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/758/0*5sJGVN6O6-ArGvl9.jpg" /><figcaption>A still from a video of N900VA’s departure from Grand Junction on the accident flight. The full video is available in the NTSB’s public docket. (NTSB)</figcaption></figure><p>One West Star technician stated that he asked the PIC whether he would be able to find a clear area to perform the test, to which the PIC replied that he would just get above the clouds. Another West Star technician reported that he was surprised by the pilots’ decision to go ahead with the test under the prevailing conditions. But the reality in the charter business is that the window in which to perform these tasks is often short and the financial consequences of delays are often steep. It’s not clear from the available documents whether there was a client waiting to board the aircraft at the other end in Gig Harbor, but it wouldn’t surprise me.</p><p>At 10:16, with the aircraft powered on, the cockpit voice recorder began capturing the sound of routine pre-flight checks, including verification of the stall warning system, which was successful. The startup sequence was wholly uneventful, and N900VA eventually taxied out to runway 11, where the pilots completed the before takeoff checklist. The checks were carried out normally with no items of note, except for one: the SIC called “anti-ice off.”</p><p>Although this comment (and the checklist itself) referred to the engine anti-ice, investigators believe that the crew didn’t turn on the wing anti-ice either, despite the presence of icing conditions along their flight path. There was nothing on the cockpit voice recording that would indicate the reason for this omission, but the NTSB speculated that they could have been concerned that the anti-icing fluid on the wing surface would affect the aircraft’s stall characteristics during the test. However, ice on the wings would obviously be even worse, and the stall test guidance states that the wings must be free of ice before initiating the test.</p><p>My understanding is that the typical move would be to fly to an area without icing conditions before performing the test, and that there is certainly no reason not to use anti-icing while en-route to such an area. I find it somewhat hard to believe that an experienced captain would consciously decide to forgo wing anti-ice, knowing that he was going to fly through icing conditions, followed by a test of the aircraft’s stall characteristics. However, there remains a strong possibility that this is what occurred.</p><p>A former Hawker pilot also told me that it was standard procedure to “prime” the TKS anti-icing system at the start of each flight by running it for a certain period of time. This was because the pores in the leading edge could become clogged if fluid was not forced through them regularly. However, because most aircraft don’t use fluid-based anti-icing systems, and because the Hawker is out of production, he told me that it could be hard to find the correct type of fluid at most airports, and as a result it had become common for operators to forgo priming the TKS in order to make the fluid supply last longer. This raises the possibility that the pilots were habitually leaving the TKS off even when the checklist called for it to be turned on. If so, then it’s plausible that a crew might neglect to consider that they should turn it on during icing conditions, especially if they were recently concerned about the fluid level. However, I have no evidence that this was occurring at Clay Lacy, or that the practice played any role in the pilots’ omission to engage wing anti-ice.</p><p>Regardless, what we do know is that at 10:36 and 59 seconds, N900VA began its takeoff roll, with anti-ice off. Liftoff occurred 25 seconds later, and the plane soon climbed away into the overcast layer, aiming for clear air above.</p><p>As the aircraft climbed through the clouds, it would have started picking up ice on all forward-facing surfaces, including the wing leading edges. A study by the National Center for Atmospheric Research calculated that during this time, up to 1 millimeter of ice could have accumulated on the leading edges, which is enough to measurably reduce the stall angle of attack.</p><p>During climb, the crew contacted Denver approach and reported that they planned to do some air work in the “mid-teens” for about ten minutes. An altitude in the mid-teens would have put them right in the middle of the prescribed altitude range for the stall tests.</p><p>In the cockpit, the atmosphere was casual and friendly. The PIC seemed relaxed as he said, “and [engage] autopilot, what the hell, let’s go crazy.” Later, the SIC called out, “There is a bird,” to which the PIC comically replied, “Yuppers.”</p><p>At 10:39, Denver approach cleared them to climb to 26,000 feet and to contact Denver center. The SIC then asked the PIC, “What altitude, to whatever some — ”</p><p>The PIC replied, “Yeah, let’s just — yeah, climbing to two si — tell ’em we’ll request a[n] altitude once we get above in VMC.” VMC stands for visual meteorological conditions; that is, the absence of clouds.</p><p>This statement was consistent with his plan to climb above the clouds to perform the test, as he had conveyed to the West Star technician. However, with the reported cloud tops near the maximum stall test altitude, that plan would prove tricky.</p><p>As they climbed through the clouds, the SIC announced that he had finished the after takeoff checklist, then added, “Alright, cooking with gas, captain.”</p><p>“Yeah baby!” the PIC exclaimed.</p><p>“No surging engines, nothing, I don’t see any issues,” said the SIC.</p><p>“Nope.”</p><p>“Most importantly, does the WiFi work,” the SIC continued.</p><p>“Yup,” the PIC said with a chuckle.</p><p>A few seconds later, the PIC changed topics. “Ask ’em if we can get a block from 180 to 200, if we can’t do that then — yeah, let’s just see if we can do that.”</p><p>Here the PIC was making a deliberate choice to deviate from the stall test procedure. The prescribed altitude range for the test was from 10,000 to 18,000 feet, but due to the high cloud tops, he was now requesting an altitude block between 18,000 and 20,000 feet in which to perform the test, which was too high. The decision showed a casual disregard for the guidance in the manual. My opinion is that this may have stemmed from a feeling that the stall test was a box to tick on their way home, rather than a serious check of the aircraft’s airworthiness, which would be done under clearly circumscribed conditions in order to ensure the reproducibility of the test. It’s also possible, given the icing conditions and his non-use of anti-ice, that the PIC was more worried about ensuring he performed the stall test in clear air, where the plane would not pick up ice, than he was about adhering to the altitude restriction. However, any ice that had accumulated on the wings would remain there for some time, so this move would provide no benefit if the test was initiated too soon.</p><p>At 10:42, Denver center cleared N900VA to maintain a block altitude of 18,000 to 20,000 feet as requested, and the PIC called for the SIC to set 20,000 feet in the autopilot. Around this time, the aircraft broke through the clouds and emerged on top, around 15,300 feet. The CVR captured the PIC briefing the SIC, presumably with reference to a table of airspeeds: “Alright so we got ahhh, flaps zero target, and I’m just gonna log your numbers here, here, here, here…”</p><p>A minute later, Denver center asked how long the air work would take, to which the SIC again stated “ten minutes or less.” However, according to Gary Grommet, the former chief test pilot at the Hawker factory in Wichita, a full stall test usually takes a little bit under 30 minutes. The pilots were discussing a plan to conduct the test in the “clean” configuration with flaps and gear retracted; it’s unclear from the transcript whether they understood that other flap and gear configurations needed to be tested as well. In his submission to the NTSB, Grommet mentioned that line pilots sometimes omitted to perform the test in all configurations, even though it’s possible for an aircraft to pass in one configuration and fail in another.</p><p>Nevertheless, Denver Center granted the block altitude, and having now leveled off at 20,000 feet, the pilots decided to begin the test. They appeared unaware of the possibility of ice on the wings.</p><p>“Alright, here we go my friend,” the PIC began.</p><p>“So we’re taking indicateds right?” the SIC asked, referring to indicated airspeed.</p><p>“Ah yeah, indicated, we’re looking for shaker, pusher, I’ll call mark on pusher if you can’t see it for some reason,” the PIC explained.</p><p>The SIC acknowledged, and the PIC then disconnected the autopilot and reduced thrust, beginning a steady 1 knot per second deceleration from 219 knots.</p><p>“Good [expletive] man, what are they doing?” the SIC asked.</p><p>“Are we having fun yet?” the PIC asked.</p><p>“Slowly,” said the SIC.</p><p>“Why can’t I do this in the sim?” the PIC chuckled. “I’m all over the place in the sim.”</p><p>Seconds later, a landing gear warning sounded, informing the crew that they were flying below 150 knots with power at idle but hadn’t lowered the landing gear. This warning was expected during a stall test and the crew simply noted it and moved on. “That’s a beer,” the PIC called out.</p><p>For 40 seconds, the pilots silently watched the speed bleed away, until at 10:46 and 33 seconds, the stick shaker sounded at a speed of 118 knots. At almost exactly the same time, the SIC called out “One nineteen,” which was the speed where they expected the stick shaker to activate, according to the tables from the AFM.</p><p>What the pilots did not realize was that by the time the stick shaker went off, they were already in trouble.</p><p>In fact, flight data showed that the aircraft stalled almost simultaneously with the warning. Because the stick shaker should activate at a speed 7–9% above the stall speed, and 118 knots was within the expected stick shaker activation tolerance at their weight and configuration, the only reason the stall should have occurred so close to the time of the warning was because the stall itself began too early, not because the stick shaker activated too late.</p><p>The NTSB considered the possibility that the maintenance work had contaminated the leading edge or altered the position of the stall triggers, but both of these possibilities were considered unlikely. No physical evidence remained, but West Star Aviation had carried out so many inspections that it was hard to believe any contaminants could have gone undetected. Furthermore, according to Grommet, West Star Aviation was aware that following the maintenance manual by resetting the stall triggers to the “standard” position would render the stall characteristics unairworthy, and as a result their in-house practice was to measure the position of the stall triggers before removal of the TKS panels so that any accidental movement could be identified and corrected following reinstallation. Thus, there is no reason to believe that any action by West Star could have led to the aircraft stalling too early.</p><p>Instead, the most likely reason for the early stall was ice on the wings. Since N900VA had just climbed through known icing conditions with the anti-ice system turned off, it was quite likely that up to 1 millimeter of ice had accumulated on the leading edges, causing airflow separation to begin at a lower than expected angle of attack.</p><p>If the pilots had flown to a clear area far from the icing conditions, the ice might have had time to break off or sublimate. Or, if they had turned on the anti-ice system, no ice would have accumulated in the first place, and the fluid also would have eventually blown away given sufficient flight time. Or the pilots could even have checked for ice by arming the Hawker’s built-in ice detection system, but there was no evidence that they had turned it on. In the end, it seems they did nothing to prevent ice contamination from affecting the stall test — and we will never fully understand why.</p><p>Unfortunately, the early stall caught the pilots completely by surprise. Unaware that the airplane was already in a stalled condition, they did not immediately attempt to recover, and four seconds after the start of the stick shaker the airflow began to separate over the ailerons. The airplane abruptly rolled 45 degrees to the right before the PIC managed to counter with full left aileron, but at the same time he pulled back on his control column, increasing the angle of attack and making the stall worse. A pilot with the PIC’s resumé would be wildly aware that stall recovery requires pitching down to reduce the AOA, so this action was likely instinctive. It may have even been a panic reaction to the unexpected aircraft behavior, given that he had never previously experienced abnormal stall behavior in the Hawker.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*mqLisswDibKYv6-3" /><figcaption>Flight data from N900VA. Note control column position going to full nose up while pitch falls below the horizon and airspeed and altitude data become unreliable. (NTSB)</figcaption></figure><p>Recognizing that something was seriously amiss, the PIC uttered several expletives and advanced the thrust levers to high power. The CVR captured the sound of the engines spooling up, but without reducing the AOA, the aircraft did not exit the stall, and the flight data recorder captured the sudden loss of lift — what pilots call a “break” — in the form of an abrupt reduction in vertical acceleration to 0.6 G, accompanied by a sharp uncommanded decrease in pitch angle from 15 to 6 degrees.</p><p>Two seconds after the break, at an airspeed of 115 knots, the stick pusher kicked in. The speed and AOA at which it activated were standard, but it had come too late to prevent the ice-induced stall from occurring.</p><p>With the AOA still above the stall threshold, airflow over the ailerons remained separated, and the right bank increased to 72 degrees despite the PIC’s full left aileron inputs. A master caution light illuminated, and the ground proximity warning system blared, “BANK ANGLE! BANK ANGLE!” Simultaneously, the pitch fell below the horizon to almost -8 degrees, but the plane was now falling so steeply that the AOA remained above the stall threshold.</p><p>It has to be noted that while the stall guidance in the AFM says that the bank angle should be kept to within 20 degrees by use of the ailerons, this is a test procedure, designed to detect normal versus abnormal roll behavior, and not a recovery technique. If the aircraft is rolling in a stall, the only way to regain roll control is to reduce the AOA.</p><p>Four seconds after the break, the right bank peaked at 85 degrees before abruptly reversing to the left as the pitch fell below -20 degrees, filling the windscreen with white as the plane plunged toward the clouds. The PIC continued to shout expletives as he wrestled for control, but flight data showed that from this point his control column was pinned at the full nose up position, whereas at this point full nose down was probably required to reduce the AOA and escape the stall. This input would have overridden the stick pusher.</p><p>Why an incredibly experienced pilot, a pilot who had personally designed upset recovery and stall recognition training programs, would react in this manner is difficult to understand. However, I think the role of the startle factor should not be understated. The evidence suggests that neither pilot was expecting the aircraft to actually stall, and even if they were, they certainly weren’t expecting it to stall before the stick pusher and with a very sharp roll component. The NTSB noted that no Hawker line pilot gets to experience stall behavior in the real aircraft, because it’s too dangerous. Stick pusher demonstrations and stall recovery scenarios are practiced in the simulator, but the simulator stalls quite gracefully; it’s not programmed to include an abrupt loss of roll control, and recovery is rather straightforward. Pilots also did not practice stalls with ice on the wings, which could cause abnormal behavior, nor are the simulators capable of reproducing such behavior.</p><p>Another significant observation is that pilots commonly react to the stick pusher by attempting to override it. Any instructor who has performed a stick pusher demonstration will tell you that almost everyone’s instinct upon seeing the control column jerk forward all by itself is to try and pull it back again. The purpose of stick pusher demonstrations is to excise this tendency through repeated practice during the training phase. But if the stick pusher activates while the pilot is already under the influence of the startle effect, that instinctive reaction could return, causing the pilot to pull the nose up instead of letting the stick pusher recover the aircraft.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8pn3q8WNYOxnuW6wdp3UOg.png" /><figcaption>3-D visualization of the flight path. (NTSB)</figcaption></figure><p>Once the PIC overrode the stick pusher, the remaining time for recovery was probably very short, maybe non-existent. Over the next few seconds, the airplane rolled left so rapidly that it passed through the inverted position and back to level flight, completing a full 360-degree rotation, accompanied by panicked shouts like “oh my god” and “# me.” Exiting the roll, the pitch angle dropped to a terrifying -75 degrees, but the plane was now falling almost vertically, and the angle of attack remained above the stall threshold. By that point, the plane was most likely in a deep stall, rendering recovery impossible.</p><p>As N900VA fell from the sky, the aircraft began to rotate to the right about its yaw axis, and the nose came up almost to the horizon, sending the plane into a flat spin. Like a leaf she plunged through the roiling clouds, her cockpit filled with a horrid symphony of noises, from the roar of the stall buffet to the death rattle of the stick shaker to the pilots’ frantic exhortations.</p><p><em>“I can’t hold it, I can’t # hold it! I can’t hold it!”</em></p><p><em>“What are you off the rudder?”</em></p><p><em>“Yeah!”</em></p><p><em>“You got nose down? You got speed?”</em></p><p><em>“I got…”</em></p><p><em>“Speed brakes in or out? Dive it or something, # #!”</em></p><p><em>“#!”</em></p><p><em>“TWENTY FIVE HUNDRED.”</em></p><p><em>“Opposite!”</em></p><p><em>“Ahh I can’t I can’t I can’t!”</em></p><p><em>“Forward, put it forward, put it forward!”</em></p><p><em>“TERRAIN! TERRAIN! PULL UP! PULL UP!”</em></p><p><em>“Oh #!”</em></p><p><em>“We’re dead.”</em></p><p>And so ends the transcript.</p><p>◊◊◊</p><p>At 10:47 and 44 seconds, after falling for just over one minute, N900VA crashed belly-first into the desert just beyond the Colorado-Utah border, flattening an empty stretch of sage about 8 kilometers north of Interstate 70. The airplane exploded on impact and was destroyed, killing both pilots instantly.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*NurEeYMNZf6iFckC.jpg" /><figcaption>The wreckage was tightly contained within a small area, because the plane impacted with almost no forward momentum. (NTSB)</figcaption></figure><p>The crash of N900VA brought considerable attention to the history of Hawker stall test incidents and the wisdom of allowing line pilots to perform them. The fact is that these pilots were far from the first to get into trouble during a stall test or demonstration, and they would not be the last.</p><p>For instance, in 2003, a Hawker 700 crashed while conducting a training flight near Beaumont, Texas, during an approach to stall demonstration, killing all 3 crewmembers. The NTSB found that the instructor did not follow the procedure for a stall demonstration, beginning the maneuver at an altitude that was too low and allowing the airspeed to decrease too rapidly.</p><p>Additionally, in 2006, a Hawker 800A was involved in a near-crash in Nebraska during a post-maintenance stall test flown by a factory marketing pilot who was not specifically trained to do stall tests. The pilots conducted the test under icing conditions, leading to a premature stall. Fortunately, a deep stall did not develop, and the pilot was able to recover in visual conditions after losing considerable altitude; however, the recovery maneuver involved high G-loads, causing substantial damage. The occupants were not injured.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*T0F4zexpSm3YAxpT.jpeg" /><figcaption>First responders at the scene of the crash of N900VA. (WBRC)</figcaption></figure><p>Before the loss of N900VA, there had not been any other fatal accidents during stall tests or demonstrations, but in his submission to the NTSB, former Hawker factory chief test pilot Gary Grommet mentioned that there have been other in-flight loss of control events, some involving the loss of thousands of feet of altitude, many of which were not subject to formal investigation. <em>“I once counseled a pilot who explained he went out to perform a stall test ‘and just about died … twice’ because he had a small accretion of ice on the wings,”</em> Grommet wrote, adding,<em> “I recently heard a report of a pilot who ‘went inverted and lost 7000 feet’ [while] performing a stall test.”</em></p><p>While researching for this article, I attempted to track down Gary Grommet for an interview, seeing as he has conducted more Hawker stall tests than anyone alive, but as of this writing he has not responded to my requests for comment.</p><p>◊◊◊</p><p>Then, on October 16, 2025, while the investigation into N900VA was wrapping up, tragedy struck again.</p><p>That date was crisp and sunny in Battle Creek, Michigan, where a Hawker 800XP was being prepared for release from regular maintenance at a facility belonging to Duncan Aviation. The aircraft, registered to Mexican charter company Aerolineas del Centro as XA-JMR, had been in Battle Creek since March for the same battery of checks as N900VA, including removal and inspection of the wing leading edges. Three crewmembers were sent from Mexico to bring it home, but a stall test was required before it could return to service.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1000/0*JiZCLuLqPiAU7V38" /><figcaption>XA-JMR, the aircraft involved in the Michigan accident. (Bureau of Aircraft Accidents Archives)</figcaption></figure><p>According to the NTSB’s bare-bones preliminary report, Duncan Aviation gave the captain a list of experienced test pilots who could be hired to perform the stall test. However, the crew from Aerolineas del Centro were unable to coordinate a flight with any of those test pilots, so they decided to perform the flight themselves. It’s unclear whether any of the crewmembers had prior experience performing Hawker stall tests, as required by the SRM and the POM.</p><p>At 17:08, XA-JMR departed for the test flight with three pilots on board. One of them was riding as a passenger, which is at least questionable, if not outright irresponsible, on a test flight.</p><p>After an uneventful climb, the aircraft leveled off at 15,000 feet, and the crew requested a block altitude from 14,000 to 16,000 to perform air work. The request was granted, and at 17:27 the aircraft began to decelerate, indicating that the stall test had commenced. Subsequently, the aircraft started to lose altitude rapidly, and a broken inadvertent radio transmission in Spanish, “<em>Now go down,” </em>was heard. The air traffic controller, seeking clarification, called the aircraft, and one of the pilots replied, “We are in… stall recovery, stall recovery sorry!” Further attempts to raise the aircraft were unsuccessful.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/225/0*oparTX4wqGRQPmcn" /><figcaption>A view of the smoke cloud from the crash, scene from the Interstate. (WLNS)</figcaption></figure><p>At about 17:30, witnesses on and near Interstate 69 near Bath Township saw the aircraft falling from a clear sky in an apparent flat spin. It then disappeared behind the tree line, followed by a distant fireball and cloud of smoke. Minutes later, the pilot of a Southwest Airlines flight confirmed sighting the smoke cloud about a half mile from the Interstate. Emergency services arrived soon after and extinguished the fire, but all three occupants had been killed on impact.</p><p>The NTSB investigation into the crash of XA-JMR is still ongoing at the time of this writing, and won’t be finished for another year or more. If any of the findings significantly alter the main points of this article, then I’ll come back and update it. But for now, this appears to be another stall test accident similar to N900VA. The main question — one I can’t answer at this time — is why the aircraft stalled and why the pilots did not recover, since XA-JMR was not in or near icing conditions at the time of the accident.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/741/0*vkh2OBDM38ocpLsf" /><figcaption>The wreckage of XA-JMR where it came to rest in the forest. (NTSB)</figcaption></figure><p>Needless to say, a second crash during a stall test involving a Hawker in less than 2 years raised serious alarm in the aviation industry and especially at the NTSB, where investigators felt pressure to take immediate action to avoid further accidents. As a result, one month after the crash in Michigan the NTSB released a slate of urgent safety recommendations intended to make Hawker stall tests safer. In its press release, the agency wrote, <em>“We are concerned that, due to deficiencies we identified in the information available to airplane owners, operators, and pilots related to the training and procedures needed to safely perform manufacturer-required post-maintenance stall test flights in certain Hawker airplane models, other flight crews tasked to perform such flights may be similarly unprepared.”</em> The recommended corrective actions included the following:</p><p>- Textron Aviation should define specific pilot training and experience criteria for pilots performing stall tests in all Hawker models.</p><p>- Textron Aviation should develop a stall test procedure that describes which stall characteristics are unacceptable, as well as recovery procedures and any other safety considerations required to ensure preparedness.</p><p>- Textron Aviation should review the Hawker’s POM and AFM and ensure that they describe the effects of wing surface anomalies, including the possibility of a stall before the stick shaker/pusher, unacceptable stall characteristics, and recovery from adverse stall behavior.</p><p>- Textron Aviation and the National Business Aviation Association should inform all operators of the circumstances of the accidents to increase their awareness of unacceptable stall characteristics, such as 360-degree rolls or spin entry, that could be encountered during a stall test, and to make them aware that the training and experience level required for stall test flights <em>“exceeds that which is typically provided to operational line pilots.”</em></p><p>- The Federal Aviation Administration should require Textron Aviation to accomplish the above recommendations.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*rFH71mn_N8MlDlGz" /><figcaption>Smoke rises from the crash site of XA-JMR. (CNN)</figcaption></figure><p>One of the major questions I set out to answer while researching for this story is whether these recommendations address the deeper causes of the Hawker stall test accidents. And to understand why these accidents involve Hawkers, and not any number of business jets with similar designs, we have to dive into the messy history of Hawker stall tests, from the certification requirements that necessitate them, to the way pilots have been performing them. Much of the following information comes from Gary Grommet, and while I was unable to interview him, his contribution is still much appreciated.</p><p>◊◊◊</p><p>The Hawker is not the only business jet that requires post-maintenance stall tests under certain circumstances; in fact, such a requirement is not unusual among business jets of the Hawker’s vintage. However, according to Grommet, the Hawker was the only such model whose maintenance manual did not require that a trained factory test pilot carry out the stall test.</p><p>It has to be noted here that there’s no such thing as a “test pilot” certificate handed out by the FAA. The title is often thrown around like it means something all on its own, but it really doesn’t. If you’re flying an aircraft with potentially unairworthy characteristics in order to verify its airworthiness, you are a test pilot, whether you realize it or not. The key modifier, then, is a <em>factory-trained</em> test pilot, meaning a pilot who received training on the conduct of test flights directly from the aircraft manufacturer.</p><p>A pilot who receives such training is aware of the full breadth of possible aircraft behaviors, both acceptable and unacceptable, and has practiced them in the simulator to the extent possible. They will also be aware of factors that could affect aircraft performance during the stall test, factors that could affect recovery, and the specific recovery techniques required to overcome abnormal stall behaviors. There is little doubt in my mind that if the pilots of N900VA had received this type of training from the factory, they would still be alive. In fact, they probably wouldn’t have attempted the test at all, given the conditions. An untrained test pilot might start violating standard operating procedures due to the development of a “test flight mindset,” in which they start acting as though deviating from one norm permits deviation from others, whereas a trained test pilot understands that the need to slow down to follow the stall test procedure does not override the AFM requirement to maintain a speed of at least 180 knots in icing conditions or with ice on the wings.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*PbBlW0iId8QHhkhR" /><figcaption>The remains of N900VA’s tail section lie a short distance away from the main wreckage. (KJCT)</figcaption></figure><p>As for why the Hawker maintenance manual and POM didn’t explicitly require a factory-trained test pilot to conduct stall tests, the reason has been lost to time. The original design engineers who worked on the type 60 years ago can’t be reached for comment, and with the type certificate having passed through 6 or 7 different hands in the decades since, a lot of institutional knowledge has been lost. So it’s not clear whether anyone knows the answer.</p><p>What we do know is that over time, the number of stall tests that are required to be performed has increased.</p><p>Originally, a stall test was only required if the leading edge, including the stall triggers, was completely replaced with a new component, which occurred rarely. But in 2006, in the aftermath of the near crash in Nebraska, Raytheon (the type certificate holder at the time) made several reforms to the stall test criteria.</p><p>Raytheon’s primary response to that incident was to adjust the wording in the POM to mention that the pilot should have “prior experience performing stall tests in the Hawker.” However, internally, Raytheon stopped all tests until they had verified that all pilots performing the tests had received appropriate training, and yet they did not mandate any such training for stall tests conducted by aircraft operators. The company even drafted a stall test training syllabus, which it never published, preventing operators from using it. Gary Grommet, who was the chief test pilot at Raytheon’s Hawker factory at the time, wrote that it was “hypocritical” to require special training internally while publicly maintaining the position that any pilot with certain “experience” could perform the test.</p><p>At the same time, Raytheon also updated the maintenance manual to require a stall test any time the leading edge or TKS panel was removed for any reason, even if the same panel was then reinstalled. Presumably they believed that the stall triggers could be moved during this type of work, or that contamination could be introduced, and that it would be best to check whether the stall characteristics had been altered. However, this had the effect of greatly increasing the number of stall tests, because removal and reinstallation of the same panel happens much more frequently than outright replacement. Removal and reinstallation occurs every time the wing undergoes a regular inspection for cracks or corrosion, which happens on each aircraft every few years. And according to the former factory-trained Hawker pilot I spoke to, pilots’ habit of neglecting to prime the TKS anti-ice system sometimes caused the pores in the TKS panel to become clogged, necessitating removal for cleaning, which might also result in a stall test.</p><p>It isn’t clear to me from the available evidence whether Raytheon considered the risk that would be incurred by increasing the number of stall tests when they made this rule change. Nor do I have data supporting that the number of in-flight upsets during stall tests increased as a result of the rule change, although anecdotally, it seems like it did.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*DP1zA-5Jl70-ry275yYVwg.png" /><figcaption>Another view of the wreckage of N900VA, with annotations. (NTSB)</figcaption></figure><p>At the same time, Grommet points out another paradox in the manufacturer’s approach. In his opinion, which is based on a detailed reading of the applicable regulations, the stall test is an <em>airworthiness requirement</em>, meaning that the test is required in order to prove that the aircraft meets the airworthiness standard set forth in its FAA type certificate. If the stall behavior is different from that standard, then the aircraft is not airworthy. And yet, line pilots delegated to perform stall tests were not given the criteria necessary to check whether the stall characteristics were in fact airworthy. According to Grommet, the only document that provides a step-by-step process for determining whether the Hawker’s stall characteristics meet the certification basis is the manufacturer’s Production Flight Test Procedure, or PFTP, which is not publicly available.</p><p>Although the maintenance manual directs pilots to conduct the test “in accordance with the Flight Manual procedures,” the AFM does not actually contain a stall <em>test</em> procedure, only a stall procedure. In fact, in his submission to the NTSB, Grommet writes, <em>“There are no data in the Flight Manual for the CG </em>[Center of Gravity]<em> range for the test (the </em>[ AFM table of stick shaker/pusher speeds]<em> is at full forward CG), no required configurations… no guidance that stall tests be performed at idle, no tolerances for achieved shaker or pusher speeds, no safety speeds at which to abort the test, as there are in the PFTP.” </em>Furthermore, while the AFM stall procedure mentions “aileron snatch” and “overbalanced ailerons” as possible abnormal stall characteristics, there is no definition of these terms that pilots could use to determine whether these unairworthy characteristics may have been encountered.</p><p>This lack of a strictly standardized stall test procedure available to line pilots has resulted in a high degree of variance in the adequacy of the tests performed. According to Grommet, some pilots fail to test in all required configurations; some stop at the stick shaker and fail to go to the stick pusher; some perform the test with ice on the wings or the wrong center of gravity. And when a test doesn’t pass, many line pilots don’t have the technical knowledge required to articulate to the maintenance technicians how the problem should be corrected, which could result in improper adjustments to the stall triggers. Any such adjustments should be followed by another stall test, but this was not always done. As a result of these factors, it’s Grommet’s belief that any number of Hawkers currently in service could be legally unairworthy because the stall tests were not conducted in a manner that would identify improperly adjusted stall triggers.</p><p>In light of these facts, it’s evident that the provisions in the SRM and POM delineating who can perform stall tests don’t adequately support the airworthiness of the aircraft, at least with the way operators have traditionally interpreted them. But Grommet believes most operators are not interpreting the provisions correctly. In his view, a strict, legal reading of the phrase, “<em>a pilot familiar with the stall identification system and stall characteristics of the 750, 800, 800XP, 850XP, and 900XP series</em>,” could imply that experience with all of those aircraft is required. However, this is probably not what the author meant. Instead, Grommet’s preferred reading is that “familiar with the… stall characteristics” means <em>familiar with the certification basis of the Hawker’s aerodynamic characteristics under Part 25 of the Federal Aviation Regulations.</em> This would be consistent with the treatment of stall tests as a requirement to ensure the “continuing airworthiness” of the aircraft; that is, the assurance that the aircraft continues to comply with the original certification basis as it ages. And as Grommet succinctly puts it, <em>“Airworthiness is not determined by a pilot’s experience, it is determined by procedural means to a standard.”</em></p><p>The takeaway, then, is that the SRM provision may have been written with the intent to require a factory-trained test pilot to perform the stall test, only for this intent to be lost over time. The result has been the widespread use of ordinary line pilots to perform stall tests, endangering air crews who are unprepared for abnormal stall behavior and improperly equipped to evaluate the airworthiness of the aircraft.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*1x3-PBNB4KlvvQf1" /><figcaption>3-D visualization of the last flight of XA-JMR, including its abrupt end. (Flightradar24)</figcaption></figure><p>Who, then, should perform Hawker stall tests? The consensus seems to be that, for safety reasons, the left seat should be occupied by a factory-trained test pilot; and for airworthiness reasons, that test pilot should be equipped with a test procedure designed to check the aircraft’s compliance with its certification basis, such as the PFTP. The NTSB’s recommendations, if adopted, will go a long way toward bringing this about.</p><p>In debates about the Hawker stall test accidents, there are diverging opinions on whether the right seat should also be occupied by a factory-trained test pilot. In one infamous thread on the Reddit board r/flying, for example, multiple users reacted strongly and negatively to a post by a relatively new SIC who planned to fly in the right seat on a Hawker stall test with a factory-trained test pilot in the left seat. Some even told him to start drafting a will. However, the opinion of both Gary Grommet and the factory-trained test pilot that I spoke to is that any SIC with a Hawker type rating is capable of performing the right-seat duty during a stall test, which is basically just calling out speeds from a table while the PIC flies the airplane and evaluates its handling. Therefore, I see no reason why operators should be required to hire two test pilots when one seems to be enough.</p><p>However, as the crash of XA-JMR illustrates, finding a qualified test pilot able to meet the operator’s scheduling requirements can be difficult. The fact is that the Hawker factory hasn’t been in operation for 13 years and no new Hawkers will ever be made, which means that the pool of factory-trained test pilots can only ever get smaller, and the pressure to use regular line pilots will only become greater. So while a rule requiring a factory-trained test pilot will improve safety, it could, in time, become a significant hindrance to Hawker operations. The solution to this paradox is to accompany the new requirement with a rule change that would reduce the number of stall tests that must be performed. Such a proposal was not among the NTSB’s recommendations.</p><p>In his submission to the NTSB, Gary Grommet lays out how this might be done. For example, one low-hanging fruit is a reversal of the 2006 rule change that ballooned the number of stall tests in the first place. By updating the maintenance manual to instruct technicians to measure the position of the stall triggers before removing the TKS panel, and measuring again to confirm that they’re still in the same position after reinstallation — as some facilities like West Star Aviation are already doing — the requirement for a stall test following removal of a TKS panel could be eliminated.</p><p>This change would not eliminate the need to perform a stall test following replacement of the TKS panel; only removal and reinstallation of an existing panel. That’s because the position of the stall trigger is currently measured from the edge of the TKS panel itself, so when a new panel is installed, perhaps with its own slight variations, that original datum is no longer present. Instead, Grommet suggests that these stall tests could also be eliminated if the standard procedure was to measure from the edge of the wing structure, which never changes. In combination with the change described in the previous paragraph, these reforms would eliminate most stall tests.</p><p>Additionally, Grommet wrote that the robustness of the above measures could be improved if the stall triggers were fixed in place once the airworthiness of the airplane’s stall characteristics has been confirmed. This would all on its own eliminate the cause of most of the failed stall tests he had personally experienced, which were mainly due to inadvertent rather than intentional movement of the stall triggers.</p><p>While I’m not in a position to evaluate Grommet’s proposed solutions, I have to agree that the safety improvements proposed by the NTSB might be undermined if measures are not taken to reduce the number of stall tests. This is not an unsolvable issue. The vast majority of transport aircraft do not require flight tests to ensure the continuing airworthiness of their aerodynamic characteristics, and it seems reasonable that the Hawker could be brought into such company.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/900/0*zoAILxovm2wm9BiB" /><figcaption>Rain falls over the high desert near the crash site of N900VA. (Western Slope News Now)</figcaption></figure><p>◊◊◊</p><p>It is likely that changes will be made to how and whether Hawker stall tests are performed in the future, given the NTSB recommendations and the attention that has been drawn to the subject. As I write this, the exact form that those changes will take is yet to be determined, and it’s not my place to say what it will be. My only hope is that this article leaves the reader better informed about what has been happening, why it might be happening, and what experts think ought to be done about it.</p><p>Unfortunately, whatever changes may come, they will be too late to save the ill-fated crews of N900VA and XA-JMR. The last lines of N900VA’s cockpit voice recording will stick with me for a long time, echoing forever, backed by the choir of the stick shaker. Nobody should have to go through what they did, and yet not only did it happen, it happened twice. Two business jets, two crashes, five lives lost, others shattered by grief — and for what? Because of an ambiguous 60-year-old line in a manual? These tragedies were preventable, if only more people had questioned the system, but sometimes it takes a tragedy to see the forest for the trees.</p><p>_______________________________________________________________</p><p><em>You can also see my work on Petter Hornfeldt’s YouTube channel “Mentour Pilot,” where I’m employed as a script writer and researcher.</em></p><p><em>Don’t forget to listen to Controlled Pod Into Terrain, my podcast (with slides!), where I discuss aerospace disasters with my cohosts Ariadne and J! </em><a href="https://www.youtube.com/@ControlledPodIntoTerrain"><em>Check out our channel here</em></a><em>.</em></p><p>_______________________________________________________________</p><p><a href="https://www.reddit.com/r/AdmiralCloudberg/comments/1r8dy5o/the_most_dangerous_line_behind_the_hawker_stall/?">Join the discussion of this article on Reddit</a></p><p><a href="https://www.patreon.com/Admiral_Cloudberg">Support me on Patreon</a> (Note: I do not earn money from views on Medium!)</p><p><a href="https://bsky.app/profile/kyracloudy.bsky.social">Follow me on Bluesky</a></p><p>Visit <a href="https://www.reddit.com/r/AdmiralCloudberg/">r/admiralcloudberg</a> to read and discuss over 260 similar articles</p><p><a href="https://docs.google.com/document/d/1ueJ5MCqiF0EcPMKesQuAdh7b9-OBFUtq0Qe4vsrwOUA/edit?usp=sharing"><strong>Bibliography</strong></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=85f1c79f1e0d" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Dark Networks: The 2003 Timor-Leste Il-76 crash and the global air cargo shadow industry]]></title>
            <link>https://medium.com/the-academic/dark-networks-the-2003-timor-leste-il-76-crash-and-the-global-air-cargo-shadow-industry-4e67ab377760?source=rss-e119a26506e3------2</link>
            <guid isPermaLink="false">https://medium.com/p/4e67ab377760</guid>
            <category><![CDATA[southeast-asia]]></category>
            <category><![CDATA[technology]]></category>
            <category><![CDATA[flying]]></category>
            <category><![CDATA[aviation]]></category>
            <category><![CDATA[international-relations]]></category>
            <dc:creator><![CDATA[Admiral Cloudberg]]></dc:creator>
            <pubDate>Sat, 13 Dec 2025 23:59:58 GMT</pubDate>
            <atom:updated>2026-01-15T09:20:10.481Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/500/0*jIY89RIEQNRHDGwR.jpg" /><figcaption>The massive wreckage trail of RDPL-34141 slices like a scar across the Timorese countryside. (Cameo Pourghannad)</figcaption></figure><p>On the 31st of January 2003, a huge four-engine Ilyushin Il-76 cargo plane crashed just short of the poorly developed airstrip in the town of Baucau, Timor-Leste, killing all six crewmembers. The crash was briefly noted by the world press but never made headlines, nor would it have been likely to do so, because accidents like it happen all the time.</p><p>Cargo flights into remote and impoverished warzones on behalf of short-lived paper companies form a dangerous but essential underworld of the global aviation industry, bringing crucial supplies and humanitarian aid into some of the most desperate places on earth, while simultaneously supporting a shadow industry of arms trafficking, human smuggling, tax evasion, and other criminal enterprises. These flights crash with alarming regularity, but almost all of these accidents are never properly investigated and very little is known about them — sometimes basic facts such as the number of people killed, their identities, and even whether the crash happened at all are left up for debate.</p><p>Due to a fortuitous geopolitical happenstance, the crash in Timor-Leste in 2003 did not meet that fate. The government of the tiny, newly independent island nation instead invited Australia to investigate the cause of the crash and publish a final report, shedding light on the realities of these fly-by-night freight operations, as well as the difficult circumstances and poor decision-making that doomed the six crew of the enormous Ilyushin. The investigation also provided a starting point for me to dig into the history of the owners and operators of the aircraft, in an effort to understand who was responsible for the flight and their possible connections to the broader industry of clandestine cargo. What I found was a confusing maze of shell companies, conflicting records, leases and sub-leases and re-registrations. And by the end, one thing was clear: whoever owned this plane didn’t want to be found.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*4Zlwcv4zSIN1bFhY.jpg" /><figcaption>Scenery from the beautiful coast of Timor-Leste. (Trevar Skillicorn)</figcaption></figure><p>Five hundred kilometers north of Australia, where the mighty volcanoes of the Sunda Arc descend into the glittering coral waters of the Banda Sea, lies the island of Timor. Covering an area approximately the size of Belgium, Timor is a mountainous, uplifted land, its steep-sided hills carpeted in tropical dry forests in the north and rainforests in the south, its spine deeply scored by braided rivers that rush headlong toward the turquoise ocean. It was here that an Il-76 came roaring out of the clouds on a foggy January morning in 2003, on its way to help restore one small piece of a land wracked by war and poverty, part of the vanguard of an effort to bring a tiny island nation back from the brink. And the story of that flight has to begin with the story of Timor-Leste.</p><p>European traders reached the bejeweled island in the early 16th century, and by the middle of the 18th, the Netherlands and Portugal began to establish colonies as part of their broader competition for land and resources in what is now Indonesia. After a series of defeats to the Dutch, the Portuguese presence in the region was eventually reduced to the remote eastern half of Timor, which became known in Portuguese as <em>Timor-Leste</em>, or East Timor. Ironically, the name “Timor” itself derives from the Malay word for “east,” and thus Timor-Leste, as the eastern half of the easternmost island of the Lesser Sunda chain, fittingly means <em>East East.</em></p><p>As a minor outlying colony in the vast Portuguese Empire, Timor-Leste was largely ignored, except for a steady trickle of sandalwood exports. Portugal invested almost nothing in terms of infrastructure, education, or other basic duties of government; and for a while, life for the Timorese continued much as it always had, subsisting off the land and the sea. But in the 20th century, increasing extractive efforts by Portugal, followed by the horrors of Japanese occupation and Allied resistance, devastated the island. Resistance to Portuguese rule began to grow, but Portugal, ruled by a militaristic dictatorship, refused to relinquish its remaining colonies, including Timor-Leste.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/976/0*mouCtNR37dUOB4Eh.png" /><figcaption>Location of Timor and Timor-Leste. (BBC)</figcaption></figure><p>In 1974, the Carnation Revolution overthrew the Portuguese government, and the new regime immediately began to withdraw from the colonies. Over the next several years, countries like Angola, Mozambique, and Guinea-Bissau achieved independence as Europe’s last true colonial empire finally collapsed. In Timor-Leste, the power vacuum was filled by local pro-independence factions, including the Timorese Democratic Union and the Revolutionary Front for an Independent East Timor, known as Fretilin. In August 1975, a brief civil war erupted as both factions fought the remaining Portuguese and each other, resulting in a victory by the socialist Fretilin after two weeks.</p><p>Fearing socialist influence in the region and seeing an opportunity to expand its territory, Indonesia’s military dictatorship plotted to occupy Timor-Leste before the revolutionary government could garner international recognition or support. Indonesia invaded Timor-Leste on December 7, 1975, attacking Fretilin with overwhelming force. The attack was widely seen as a violation of international law, and the United Nations Security Council unanimously called upon Indonesia to withdraw, but the invasion continued, and in fact the United States, Australia, and several other countries supplied Indonesia with weapons. Over the next three years, Indonesian forces drove Fretilin fighters into the hills and set about crushing all remaining resistance.</p><p>The Indonesian occupation of Timor-Leste was particularly brutal. Crimes confirmed by the United Nations and other official sources included but were not limited to indiscriminate massacres of entire villages, mass executions of civilians, forced starvation, forced relocation to camps, use of chemical weapons, widespread napalm bombardments, murder of surrendering civilians, sexual slavery, and forced disappearances. Estimates of the death toll during the Indonesian occupation range from around 80,000 to above 200,000, mostly civilians, out of a pre-invasion population of less than 750,000. These actions have been described as a genocide by experts on human rights abuses.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/601/0*upJvIYs12JN61IFk" /><figcaption>Indonesian armored vehicles enter Timor-Leste. (CNC archive)</figcaption></figure><p>International attention was drawn to the plight of Timor-Leste in 1991 when Indonesian forces massacred over 200 pro-independence protestors on the streets of Dili, the capital. Following the massacre, grassroots pressure began to build, and in 1996 independence leader José Ramos-Horta was awarded the Nobel Peace Prize. And finally, in 1998, Indonesian president Suharto resigned after 30 years in power, paving the way for Indonesia’s transition to democracy — and for a resolution to the conflict in Timor-Leste. International talks eventually led to the arrangement of a referendum on 5 May 1999, administered by a newly created United Nations Mission to East Timor, in which more than 75% of the population voted for independence. The bloodshed should have ended there, but sadly, it didn’t.</p><p>When it became clear that the independence vote would succeed, anti-independence militias trained by the Indonesian military rose up around the country, massacring civilians, setting fire to infrastructure, and forcing the UN observers to withdraw. In response, the United Nations assembled an Australian-led peacekeeping force to occupy the country and restore order. By the turn of the millennium, the entirety of Timor-Leste was under United Nations control, and at long last, the war was over.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/408/0*E2B7GZ-LUzjrBRr9.jpg" /><figcaption>UN Secretary General Kofi Annan and former US president Bill Clinton attend Timor-Leste’s independence ceremony in May 2002. (UN)</figcaption></figure><p>Three centuries of colonial neglect followed by 25 years of bloody conflict had left Timor-Leste with almost no foundation on which to build a functioning country. The population was desperately poor; the majority of the inhabitants were malnourished; almost no one outside a handful of major towns had access to electricity. What little infrastructure had existed now lay mostly in ruins. Industry, private or otherwise, was practically non-existent.</p><p>The goal of the United Nations in Timor-Leste was to establish some semblance of a state that could be handed over to the nascent local government at the end of the planned two-year occupation. The United Nations Transitional Administration in East Timor, or UNTAET, ultimately ran the country until its formal independence on 20 May, 2002. However, UN forces remained in the country until 2012, carrying out various administrative and law enforcement functions.</p><p>This is basically a Wikipedia summary of the events, because I’m an aviation writer, not a historian. In fact, when I started researching this case I knew next to nothing about Timor-Leste, and most of what I now know does in fact come from everyone’s favorite online rabbit hole of an encyclopedia. However, I think there’s value in reading even a Wikipedia summary of the history of Timor-Leste, not only because it’s necessary background for this story, but also because it’s practically unknown outside of the immediate region, and it was that very lack of attention that allowed such a heinous injustice to persist in the first place.</p><p>In any case, the key takeaway from this history is that Timor-Leste in 2003 was a nation that had just emerged from unimaginable horror, having achieved what generations of its people had fought for, only to face the prospect of building a country from absolutely nothing. Even in 2025, Timor-Leste is on the UN’s list of 44 Least Developed countries, with a rank of 152nd in GDP per capita and 155th in development (HDI); the World Bank ranks it last in the world in its capacity to register property, enforce contracts, and resolve insolvency. In 2015, half the population was illiterate and more than half lived on less than US$1.25 per day, and in 2010 less than 40% of the population had access to electricity.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/800/0*Tb3Z9zioK1IlyIRi" /><figcaption>Destroyed buildings line a street in Dili in March 2000. (UN/Eskinder Debebe)</figcaption></figure><p>Another grim statistic about Timor-Leste is that all of the country’s telephone infrastructure was destroyed in the violence in 1999, rendering communication with the country particularly difficult. In fact, the lack of telecommunications infrastructure in Timor-Leste was the proximate justification for the flight at the center of this story.</p><p>In 2002, UNTAET commissioned a new telecommunications system from Timor Telecom, at that time a majority-owned subsidiary of Portugal Telecom, which was to include mobile, landline, and internet infrastructure. All of that infrastructure then had to be physically transported to Timor-Leste.</p><p>At this point, a few things were never quite elucidated in my research. What we know for sure is that some of this equipment ended up in Macau in January 2003, and an unnamed Singapore-based company was made responsible for arranging its transportation from Macau to Timor-Leste. The relationship between this company and Timor Telecom was not explained in any of my sources, nor did any of them mention this company’s main area of business, or even its name. Unless this company was somehow tied to the manufacturer of the equipment, then it was presumably just a middleman.</p><p>On 20 January 2003, the Singapore-based company entered into a contract with a Cambodia-based air carrier to transport 32 tons of telecommunications equipment from Macau to Timor-Leste using an Ilyushin Il-76 cargo plane on 30 January. The final report on this accident doesn’t name any of the companies involved, but my research indicates that the Cambodian company was called Astro Air.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*ihPCpbP-ImAWJ8pf.jpg" /><figcaption>An Ilyushin Il-76TD at an ice runway in Antarctica. (Antarctic Logistics &amp; Expeditions)</figcaption></figure><p>The Ilyushin Il-76 is a high-wing, four-engine transport plane designed in the Soviet Union in the late 1960s as a strategic airlifter for both military and civilian purposes. The Il-76 features a deployable rear loading ramp, ample cargo space, a two-deck cockpit with a navigator’s station below the pilots, and hardened landing gear designed for heavy landings on unpaved airstrips. It was the backbone of the Soviet Union’s and now Russia’s strategic airlift capability, and large numbers were produced for the Soviet military. After the collapse of the Soviet Union in 1991, many of these aircraft entered the civilian market, where they were snapped up at low prices by small companies, mostly in the developing world. The planes proved popular among these companies for their low operational cost, large capacity, and ruggedness.</p><p>Pilots were also not hard to come by. With the collapse of Russia’s aviation industry, many Russian pilots lost their jobs at home and quite a few were desperate enough to take positions with small foreign operators, despite low pay and dangerous working conditions.</p><p>The particular Il-76 that was commissioned for the flight to Timor-Leste was built in 1986 in Tashkent, Uzbekistan, as an Il-76 MD, the MD designation meaning “modified/long range,” with registration CCCP-76667. Russian records show that it flew for the Soviet Air Force until 1991, then briefly for the Russian Air Force before it was transferred to the Ukrainian Air Force in 1992. It remained with the Ukrainian Air Force until 1995, when it was sold to a Ukrainian civilian company called Veteran, run by a union of veterans of the Soviet-Afghan War. During this time it was converted to an Il-76 TD, which is simply the civilian designation of the MD, and was re-registered as UR-76667. Veteran continued to operate the aircraft until July 2001, when it was sold to a company based in Sharjah in the United Arab Emirates.</p><p>This Sharjah-based company was the lynchpin of this entire story. At the time of the accident, this company still owned the aircraft, but this fact was obscured by a series of leases and sub-leases.</p><p>Astro Air, the Cambodian company that contracted with the Singapore-based company, was neither the owner nor even the operator of the aircraft. In fact, at the time of the flight to Timor-Leste, the Il-76 formerly known as CCCP-76667 was registered in Laos as RDPL-34141, and that country’s records showed it was operated by a Laos-based company that I identified as Euro-Asia Aviation (not be confused with Kazakh airline Euro Asia Air).</p><p>According to the final report, and substituting in the company names that I tracked down, it appears that on 1 November 2002, the Sharjah-based company (more on them in the latter part of this article) leased the aircraft to Euro-Asia Aviation with the stipulation that the owners would provide the flight crew and loadmaster. The lease also stated that Euro-Asia Aviation was not permitted to sub-lease the aircraft except with the owners’ written consent.</p><p>At the time of the lease, Euro-Asia Aviation did not have an air operator certificate (AOC). It got one from the Laos Department of Civil Aviation (DCA) on November 9, eight days after the lease was signed. This leads me to believe that Euro-Asia Aviation was set up specifically to operate this aircraft.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/500/0*J-0y1LsdVqkLK9ep.jpg" /><figcaption>RDPL-34141 in November 2002 wearing Aram Air livery. (Dirk Hammerschmidt via Werner Fischdick)</figcaption></figure><p>A photograph of the accident Il-76 with Laotian registration RDPL-34141 (see above) shows that this aircraft was in Sharjah in November 2002, but it wasn’t painted in the livery of Euro-Asia Aviation — instead, it was wearing the livery of an Iranian airline called Aram Air. Records show that in August 2001, one month after acquiring the accident aircraft, the Sharjah-based owner registered the aircraft in Iran as EP-ALK, then in September they leased it to an airline based in Tehran, which at least one source identifies as Atlas Air (not to be confused with the US airline of the same name). That lease lasted less than three months, and in December 2001 it was leased to Aram Air and re-registered as EP-RAB. It remained in service for Aram Air for 10 months, until its Iranian registration was canceled in October 2002, shortly before its transfer to Euro-Asia Aviation. Anecdotal sources suggest that registering the aircraft in Iran may have been a scheme to take advantage of deep fuel subsidies offered at that time by the Iranian government to Iranian air carriers.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*u20KC10A9_ngOeu3.jpg" /><figcaption>This photo shows the same aircraft, parked in the same spot and even with the same red ladder leaning against it, taken on October 31, 2002, with the aircraft still registered in Iran as EP-RAB. Note how the tail logo didn’t change after the rest of the plane was repainted. (Paul Denton)</figcaption></figure><p>Records show that a second Il-76 followed a similar path. Originally built for the Soviet Air Force as CCCP-76562, this aircraft also was transferred to the Ukrainian Air Force before ending up at Aram Air in May of 2001, where it was re-registered as EP-RAJ. My assumption is that this airplane was also owned by the same Sharjah-based company, but the records only cover operators of the aircraft, not owners. In any case, this aircraft was subsequently transferred to Euro-Asia Aviation and re-registered in Laos as RDPL-34138. One source states that this occurred in “late 2002” — just like RDPL-34141 — and a photograph (see below) shows this aircraft in Bratislava, Slovakia on January 9, 2003 wearing Euro-Asia Aviation livery. As far as I can tell, RDPL-34141 and RDPL-34138 were the only aircraft ever operated by Euro-Asia Aviation, and both of them most likely came from the same owner. Furthermore, while I was not able to prove that the Sharjah-based owner was also the founder of Euro-Asia Aviation, it seems a likely possibility.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*Um2mEDNSoI7qdoKA.jpg" /><figcaption>RDPL-34138, sister ship of RDPL-34141, seen in Euro Asia Aviation livery on January 9, 2003. Note the evidence of fresh paint in the same spot where the Aram Air tail logo and registration were seen in the previous photo of RDPL-34141. (Peter Marianic)</figcaption></figure><p>On 13 December 2002, four days after approving Euro-Asia Aviation’s AOC, the Laos DCA granted an airworthiness certificate to RDPL-34141. Five days after that, on 18 December, Euro-Asia Aviation entered into a sub-lease with the Cambodian company Astro Air, the terms of which stated that Euro-Asia Aviation would supply the flight crew and that the aircraft would remain registered in Laos, but Astro Air would be responsible for providing waybills and cargo documentation to the countries in which the aircraft was operated. Later, on 30 December, the Laos DCA formally recognized Astro Air as an “operator” of the aircraft. After the accident, all parties acknowledged that Euro-Asia Aviation had not sought the owner’s permission to sub-lease the aircraft to Astro Air, in violation of the original lease terms. I’ll go into more detail about the potential significance of this fact toward the end of this article.</p><p>RDPL-34141 began flying for Astro Air on 28 December 2002, with a series of flights between Mumbai and Bangkok. Although it’s unclear where the aircraft was located between being photographed in Sharjah in November and the flights to Bangkok and Mumbai in December, what I can say is that there is no evidence that the aircraft was ever in Laos, except for the fact that it had been given a Laotian airworthiness certificate, which presumably would have required an in-person inspection.</p><p>On 2 January 2003, RDPL-34141 left Bangkok and flew to Taipei, Taiwan. All indications are that it remained there for the next 28 days. A photograph of RDPL-34141 (see below) taken sometime in January 2003 shows the aircraft parked at Taipei’s Chiang Kai-shek International Airport, wearing Astro Air livery.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*ePMp2A_pOi5jk83r" /><figcaption>RDPL-34141 during its time in Taipei. The words “Astro Air” are just visible under the right-hand engines. (Sung-Yang Tong)</figcaption></figure><p>Finally, on 30 January 2003, RDPL-34141 left Taipei and flew to Macau to pick up the equipment for Timor Telecom. How the Singapore-based middleman got ahold of this plane, operated by this tangle of companies, is unknown. What is known is that the Singapore-based company appeared to treat Astro Air as the operator of the aircraft, because the contract between the two described Astro Air as the “carrier.” However, the cargo manifest for the flight to Timor-Leste identified Euro-Asia Aviation as the “carrier.”</p><p>Back on 28 January, the Singapore-based company sent a request on behalf of Astro Air to the United Nations asking for landing permission at the aerodrome in Baucau for 30 January. Although Dili is Timor-Leste’s capital and by far largest city, its runway was (and still is) too small to handle large jets like the Il-76. The only airport in the country capable of handling an Il-76 is Cakung Airport in Baucau, Timor-Leste’s second-largest “city” — although with a population of about 17,000, it’s not much of a city, and amenities are extremely limited. Cakung Airport was built in the 1940s to ensure that Portuguese Timor had an airfield capable of handling large aircraft, but it has never seen heavy use because there isn’t enough demand for travel to Timor-Leste to justify using any aircraft types that can’t land at Dili instead. Therefore, Baucau historically has seen use mainly during times of conflict when there exists a strategic airlift requirement, whether by Indonesia during the occupation or by the UN after Indonesia’s withdrawal. So by early 2003, Baucau was only seeing occasional use; anecdotally, months would sometimes pass between flights, almost all of which were in support of UN troop rotations.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*I-7ZOxsYfSOPpVVO.jpg" /><figcaption>The only aerial photo of Baucau Airport that I could find, taken 2009. (Wikimedia user Looper5920)</figcaption></figure><p>In response to the Singapore-based company’s request for landing rights, the UN approved the flight and advised that air traffic services were only available on troop rotation days. Baucau has never had an air traffic <em>control</em> service, but for troop rotations the UN did provide its own “air traffic service,” or ATS, which provided flights with information only. The UN’s response to the Singapore-based company didn’t specify which days were UN troop rotation days, nor did the company ask.</p><p>Instead, later that same day, the Singapore-based company contacted an unnamed Dili-based freight forwarding company and requested that they arrange payments for landing fees and provision of ATS at Baucau for the incoming flight. The Dili-based company then contacted the UN and received a quote for the stated services, as well as firefighting services and security. According to UN Air Operations, the Dili-based company replied that the only service that would be needed was help with unloading the cargo. The company never paid a cent to the UN for any services because they reportedly never received an invoice, while the UN Mission in East Timor stated that they never received any request for air traffic services from anyone associated with the operation.</p><p>This sequence of events raises several questions, none of which have straightforward answers. My educated guess is that the quote offered by the UN for the provision of airport services was likely quite steep, possibly beyond the limited budget of any of the companies involved, and that someone at some level of the operation probably decided not to bother. However, as we will soon see, this information doesn’t appear to have been passed to the flight crew. Nor is it clear who actually made the decision not to request air traffic services. In fact, the General Director of Euro-Asia Aviation later told investigators that the entire 28 January request for landing permission at Baucau had been sent without his company’s authorization, although it’s unclear whether this was the result of a miscommunication or whether the General Director was simply trying to shield himself from liability.</p><p>◊◊◊</p><p>Meanwhile on 30 January, over in Taiwan, the flight crew got RDPL-34141 ready to fly and left for Macau on schedule. It wasn’t easy finding details on the flight crew, but I did eventually identify them, albeit unofficially, thanks to some Russian pilots’ forum posts from 2003. Their ages were not mentioned in the final report but some other basic information did turn up.</p><p>The pilot in command was Captain Pyotr Shadrunov (another spelling, Chadrunov, appears in the forum post, but is likely erroneous), who was a very experienced Il-76 pilot with about 14,500 total flying hours. None of the pilots’ exact Il-76 experience was available, but it was likely significant given that all of the pilots, including Shadrunov, had held Il-76 type ratings for at least ten years. The Russian forum posts state that he was from Magadan, that his father was also a pilot based in Magadan, and that he had previously flown the Il-76 in Afghanistan and Angola. Acquaintances remembered him as a man who was quick to smile.</p><p>The investigation found that Shadrunov had a Russian pilot’s license, and despite the lease terms specifying that the flight crew should meet Laotian licensing requirements, there was no evidence that the Laos DCA had authorized his Russian license as a valid alternative to a Laotian license. This was one of many paperwork discrepancies related to Laos’s seemingly non-existent monitoring of Euro-Asia Aviation and its operations.</p><p>The first officer was identified as Andrei Matvienko, who had about 6,800 total hours. According to forum posts by his former colleagues, Matvienko had previously flown the Il-76 for Rus airline (not to be confused with RusAir) until that company was shut down by the Russian transport ministry due to major flight safety violations discovered after the fatal crash of one of the airline’s Il-76s at Chkalovsky Airport in Moscow in July 2001. It just so happened that around that time, the Sharjah-based company at the heart of this story was looking for Il-76 pilots. The final report and other sources both confirm that all of the pilots worked for the Sharjah-based company, and at least one forum post states that Matvienko was in financial difficulty when he took the job.</p><p>The investigation found that Matvienko’s medical certificate was expired, and his Laotian pilot’s license did not indicate that he possessed an instrument rating (required for flight in low visibility conditions). In fact, there was no evidence that Laotian licensing law even required him to possess one, which was not in accordance with the requirements of the International Civil Aviation Organization, of which Laos is a member. However, given his previous work history, he no doubt had plenty of instrument flying experience and had certainly held an instrument rating in the past.</p><p>The third member of the flight crew was Flight Engineer Yuri Busygin (also spelled Bushigin in some forum posts, probably erroneously). He had about 5,100 hours, but little else about him is known.</p><p>The fourth member of the crew, and the second most experienced, was 58-year-old navigator Alexander Dyatlov, who had about 9,300 hours. The Russian forum posts indicate that he was a former flight test engineer at the Gromov Flight Test Institute, where he tested navigation systems, avionics, and ejection systems. He would have been sitting separately from the rest of the flight crew, down below in the navigator’s station, in his own little bubble surrounded by windows.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*Z5xSVMMbj3dpOW9v.jpg" /><figcaption>View inside the navigator’s station on a Zetavia Il-76. (FlightGlobal)</figcaption></figure><p>Two other crewmembers were also on board, whom the final report identified as loadmasters, although some unofficial sources say one of them was a mechanic, which would make sense for the type of operation they were conducting. These two men were identified as Valery Ukhvanov and Yuri Yerokhin. The forum posts state that Ukhvanov was from Belarus, making him the only person on board who was not a Russian national.</p><p>The flight crew were all professional pilots who had fallen on hard times, pushed out of Russia’s badly shrunken airline world to find themselves at the margin of the global aviation industry, stuck for long periods in unfamiliar countries far from their families. The airlines for which they flew operated largely outside any regulatory accountability structure, and they would have had little choice but to agree to inhumane working conditions, long duty days, and dangerous operations.</p><p>The reason I went so far to put names behind their titles and flight hour counts is to make it easier to remember that these men were human beings who probably didn’t want to be there. In stories like this, it’s very easy to dismiss the people who fly these types of flights as just “sketchy Russians,” as if that’s somehow an explanation for their fate — and yes, they were Russians, and yes, they were involved in some very sketchy things that I’m going to describe in detail, but they were there in that cockpit because they had to put food on the table, and when it’s 2003 and your credentials are an Il-76 type rating, this was how you did it.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ohLlNdhhzos6W2PgxOrWvg.png" /><figcaption>Map of Southeast Asia with the flight route of RDPL-34141. (Own work, map by Google)</figcaption></figure><p>On the evening of 30 January, the aircraft and crew arrived in Macau, and the cargo loading process began. The plan was to fly to Baucau later that same night, offload the cargo, then continue to Rayong, Thailand with a stopover in Makassar, Indonesia. But this plan ran into a snag right away, as it turned out that the Il-76 falls under a high-decibel noise class that was forbidden from operating at Macau during the night. As a result, the departure was delayed by 9 hours, and the flight crew left to spend the night in a hotel.</p><p>When the flight finally departed on the morning of the 31st, the flight crew probably would have felt some pressure to prevent further delays, perhaps even to make up for lost time. There is also plenty of evidence that they would rather have been just about anywhere else. For instance, investigators found that none of the pilots were wearing their uniforms, even though company policy required them to do so, which has been interpreted as a sign of detachment, or possibly a lack of respect for their employer and for themselves. It’s certainly not the mark of a flight crew who feels deeply invested in the mission at hand. But if image isn’t seen as important, then why not wear more comfortable street clothes? Given their situation, I sort of understand why they didn’t bother with uniforms.</p><p>In any case, the cruise phase was uneventful until approximately 14:26 local time in Timor-Leste, when the cockpit voice recorder captured Captain Shadrunov briefing the planned approach to Baucau.</p><p>Cakung Airport has one runway, oriented northwest to southeast, designated 14/32. Most approaches to Baucau are flown visually, but if weather conditions did not permit, then in 2003 the only available instrument procedure was an NDB approach to runway 14. This approach was based off the non-directional beacon, or NDB, co-located with the field.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zGjDdhNZ1f2mzZ3KqX7GYA.png" /><figcaption>The Jeppesen approach chart for the runway 14 NDB approach to Baucau. (ATSB)</figcaption></figure><p>An NDB is a simple radio beacon that can be tracked using an automatic direction finder, or ADF, which indicates the direction from the aircraft’s position to the beacon. The NDB approach procedure at Baucau called for the crew to overfly the NDB, then, if necessary, enter a holding pattern with outbound heading 170 and inbound 350, before flying outbound from the NDB to the north, then performing a left course reversal to head back inbound toward the NDB on a heading of 146 degrees. If the runway was not in sight by the designated missed approach point, a missed approach should be executed. The prescribed initial altitude over the NDB was 5,500 feet, followed by a continuous descent to a minimum descent altitude (MDA) of 2,260 feet (669 m), equivalent to a minimum descent height (MDH) of 531 feet (162 m) above the runway threshold elevation. Further descent was not permitted unless the runway was in sight.</p><blockquote>*Note: Throughout this article, the term “height” means height above the airfield elevation, and the term “altitude” means height above sea level. To obtain height from altitude, subtract 1,729 feet, and vice versa.</blockquote><p>This was a fairly standard NDB approach procedure with no especially unusual features except for the fact that the approach course of 146 degrees was slightly offset from the runway heading for terrain separation purposes, necessitating a minor course correction once the runway was in sight. Furthermore, while NDB approaches were already outmoded and rarely performed in many parts of the world by 2003, less developed regions still use them regularly, and these pilots’ resumés suggest they probably encountered such approaches all the time.</p><p>However, that didn’t mean the approach was simple to fly. NDB approaches demand a higher workload because, like all non-precision approaches, they provide no vertical (altitude) guidance to the flight crew; and NDBs provide less information to the flight crew than other types of radio aids, such as VORs.</p><p>At Baucau in particular, the approach was further complicated by the lack of air traffic services, which also meant that critical information like the local air pressure and barometric altimeter setting would be unavailable. Some uncontrolled airports have means to broadcast this information automatically, but Baucau was not one of them. Data from the weather observing system had to be obtained from air traffic services, which were only available for UN troop rotations. Prior to 24 January 2003, a NOTAM (notice to airmen) had warned crews that the system was faulty and that the local air pressure could be obtained by using the reported pressure in Dili and adding 320 feet to all minimum altitudes to account for the pressure difference at Baucau’s higher altitude. But on 24 January, the equipment was fixed and the NOTAM was withdrawn, leaving crews with no official way to obtain the local atmospheric pressure unless they were part of a UN troop rotation. There is no evidence that the flight crew was aware of this when they departed Macau.</p><p>Another issue with this approach was the accuracy of the available charts. The Timor-Leste Civil Aviation Division (CAD) had published official approach charts for Baucau, albeit without an accompanying aerodrome chart or other supporting documents. A NOTAM was in force advising that flight crews could acquire these charts from the CAD website, and the Singapore-based company stated that they had done so when they applied for landing rights and had then forwarded the charts to the “operator,” which in their view was probably Astro Air.</p><p>It’s unclear whether these charts ever reached the flight crew. In fact, the crew seemed to be relying on a different set of approach charts published by the Jeppesen company, which were technically valid, but were not the ones carrying the approval of the Timor-Leste CAD. It turns out that the Jeppesen charts contained a number of errors, which I’ll get into shortly. It is also worth noting that the Jeppesen charts listed all distances, speeds, and altitudes in US Imperial units, while the Il-76 instrumentation was in metric units. Most of the world uses nautical miles, knots, and feet for distance, speed, and altitude, respectively, but the former Soviet Union and China largely use kilometers, kilometers per hour, and meters for this purpose, and as such, the Il-76’s instrumentation was not originally designed to display Imperial units. The Il-76 flight manual used by the crew stated that Il-76s engaged in international operations had been modified with a backup altimeter capable of reading in feet, but it was unclear whether RDPL-34141 actually had this instrument.</p><p>With reference to the Jeppesen charts, Captain Shadrunov led a briefing for the runway 14 NDB approach. During his briefing, he said, “At Baucau we’ll land with 135 degrees NDB approach,” which was not the correct landing course — remember, the landing course was 146 degrees. He got the number 135 from reading the runway heading listed on the Jeppesen charts, which was not the same as the approach heading, and, it turns out, was flat-out wrong — the actual runway heading was 139 degrees.</p><p>Continuing the briefing, Shadrunov stated that they would approach at a speed of 250 km/h (135 kt) on the glidepath — although there was no official glidepath — and then reviewed the missed approach procedure. Reading off the Jeppesen chart, he provided the missed approach altitude and other altitudes in feet, without converting to meters, and none of the other crewmembers requested clarification.</p><p>His briefing did not cover a large number of key items, including the minimum descent altitude/height for the approach (689/162 m), the starting altitude for the approach (5,500 ft/1,676 m), the altimeter settings for Baucau, the weather at the destination, or the applicable NOTAMs. The briefing also did not mention that the minimum safe altitude (MSA) within 10 nautical miles of Baucau, applicable when flying outside of an approved airway or procedure, was 9,300 ft (2,834 m), nor that the lowest safe altitude (LSALT) in the airway from Ambon to Baucau, which they were expected to maintain until reaching the NDB, was 4,500 ft (1,372 m).</p><p>A comprehensive approach briefing is crucial to a successful approach and landing, especially in an operating environment where numerous hazards exist. The purpose of the briefing is to familiarize the entire crew with all aspects of the procedure, identify and plan around any known hazards, and ensure that all crewmembers have a shared mental model of their intentions. Failure to perform a proper approach briefing is correlated with negative outcomes.</p><p>In many cases, an inadequate approach briefing can stem from a company culture that doesn’t value or enforce adherence to standard operating procedures. However, as we will soon see, the reason that Captain Shadrunov didn’t comprehensively brief the runway 14 NDB approach procedure is probably because he had no intention to actually use it.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7F-GGpKZ9-XW-PrdrKgoIA.png" /><figcaption>An exemplar radio altimeter like the one used by First Officer Matvienko. (ATSB)</figcaption></figure><p>After the briefing, while still in cruise at 28,000 feet, the flight crew completed the before descent checklist, which was read out by navigator Dyatlov while Captain Shadrunov and First Officer Matvienko confirmed each item. This checklist included turning on their radio altimeters and setting the bugs to the standard heights.</p><p>A radio altimeter measures the aircraft’s altitude above the ground directly below it. Each pilot has a radio altimeter, which includes the ability to set a “bug,” meaning a small indicator on the instrument to remind the pilot of a reference altitude. On the Il-76, descending below the bug setting illuminates an amber light with a “delta” symbol and a pair of “decision height” annunciators on the pilots’ glare shields, while also triggering an automated voice that speaks the words “below preselected altitude” (in Russian) into the pilots’ and navigator’s headsets.</p><p>On the Il-76, standard procedure was to set the first officer’s radio altimeter bug to the “holding altitude,” which in this case was presumably the altitude of the holding pattern around the Baucau NDB, or to 750 meters (2,460 ft) if the holding altitude was higher than 750 meters, since this was the highest value the altimeter could display. At the same time, the procedure was to set the captain’s radio altimeter bug to 60 meters (197 ft), or to the MDH for the approach if the MDH was less than 60 meters.</p><p>As a personal aside, the logic of this procedure is unclear to me, because I struggle to see an operational reason to set the radio altimeter bug to a value below that of the MDH even if another altimeter has the MDH/A set already (which may not be the case, given the procedures described in the accident report). The report doesn’t say whether any of the barometric altimeters would normally be set to trigger an alert at the MDA/H, but I can say that no such alert is mentioned in the final report. So my impression, with the limited information available to me, is that setting the captain’s bug to 60 m instead of the MDH is at best not very valuable, and at worst potentially dangerous, insofar as 60 m may be considerably below the minimum for the approach, thus delaying the low altitude alert should a premature descent below the MDH occur inadvertently.</p><p>In any case, when the navigator called out for radio altimeters, both Captain Shadrunov and First Officer Matvienko replied, “ON,” and Martvienko added “on the right 750.” However, Shadrunov didn’t call out setting 60 meters on his altimeter, and in fact the investigation found that this value was not set. The reason for this omission was not determined.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*H_glVXfLw7e3oxqujd-SVQ.png" /><figcaption>The captain’s radio altimeter as it was found after the crash. The little green arrow at the top is the reference bug, which was found at the bottom of its travel range, below zero meters. (ATSB)</figcaption></figure><p>Moving forward through the checklist, Shadrunov announced that the (incorrect) landing course of 135 degrees had been set, and then he and the navigator stated that they had tuned into the Baucau NDB. Evidence shows that the NDB was set correctly, but the pilots didn’t perform the required cross-check of their selection.</p><p>At this point, with the checklist complete, Captain Shadrunov instructed First Officer Matvienko to contact Baucau ATS to receive the latest weather. Matvienko subsequently called Baucau ATS five times over the next four minutes, but he obviously received no response, because no ATS personnel were on duty. The fact the pilots even attempted to call Baucau shows that one of three things was true: either they hadn’t read the NOTAMs and didn’t know that Baucau was only staffed on UN troop rotation days; they thought it was a UN troop rotation day; or they thought someone had arranged for ATS to be provided.</p><p>The investigation was unable to determine which of these three hypotheses was correct, but personally I would be inclined to rule out that they thought a UN troop rotation was occurring, due to a lack of evidence. Given the conflicting statements from various companies about whether ATS should have been requested, it is also conceivable that the pilots had been told by someone that ATS would be available. On the other hand, there’s plenty of evidence that the pilots hadn’t read the NOTAMs that were provided to them with the dispatch paperwork, so I don’t think a miscommunication is even necessary to explain their actions here.</p><p>At 14:39, at this point still in contact with air traffic control at Ujung Padung in Indonesia, the navigator told the captain that it was time to descend to flight level 250 (25,000 feet, 7,600 meters). He then reported the descent to Ujung Padung and told the controllers that they had contact with Baucau, which he knew to be false. On the basis of this false information, the controller signed off and advised them to contact Baucau for landing. As Shadrunov initiated the descent, Matvienko tried three more times to raise Baucau tower, without success.</p><p>At 14:41, RDPL-34141 descended through 25,000 feet and entered Timor-Leste airspace. Except for Dili airport tower, there was no air traffic control facility serving any part of the country’s airspace, so aircraft operating over Timor-Leste below flight level 250 were expected to use a common frequency, similar to the common traffic advisory frequency (CTAF) used at uncontrolled airports in much of the world. The expectation is that aircraft operating within the uncontrolled airspace will use the common frequency to announce their identity, position, direction of flight, and intentions so that all aircraft understand where the traffic is and what it is going to do, for purposes of separation.</p><p>Although a NOTAM was in force advising flight crews to use the Timor Common High frequency of 123.45 MHz between 10,000 and 25,000 feet, the Il-76 crew never tuned in to this frequency and never announced their intentions. It’s unclear whether this was because they didn’t know they were supposed to use the common frequency, or whether they disregarded the requirement because they weren’t expecting to encounter any other traffic. The latter was not an unreasonable assumption in Timor-Leste, especially at the time, but it seems weird to stake one’s life on it.</p><p>Now descending blind through uncontrolled airspace, Captain Shadrunov disconnected the autopilot without telling anyone and began flying manually. Meanwhile, First Officer Matvienko tried a further 13 times to raise Baucau tower.</p><p>At 14:48, navigator Dyatlov suggested that they “make the first approach as a control and land on the second,” meaning that they should make a test approach. Shadrunov agreed with the suggestion, and added that they would turn left off the airway onto a heading of 135, which the Jeppesen chart erroneously showed as the runway heading.</p><p>“Yes, we’ll turn left and I’ll give you data for landing, will be no problems,” Dyatlov replied.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6LXRpF-h8-jTG2yr_Ubiig.png" /><figcaption>Context of the flight crew’s plan for the test approach. (Own work, map by Google)</figcaption></figure><p>This discussion showed that for the test approach, the pilots intended to leave the Ambon-Baucau airway and line up with the runway before overflying the NDB. Since this was not part of any published airway or approach procedure, the sector minimum safe altitude (MSA) applied, which would be 9,300 feet (2,835 m). There was no discussion of this fact among the crew, nor did the flight engineer or the first officer offer any comment on the plan whatsoever. The absence of these two flight crew members from the cockpit decision-making process would be noted throughout the flight, as the more experienced captain and navigator made all the decisions together, while the junior crewmembers’ input was neither solicited nor offered.</p><p>Moments later, as they approached 10,000 feet, Shadrunov asked Dyatlov for the altimeter setting.</p><p>For low altitude flight, barometric altimeters must be calibrated according to the local sea level pressure, known as QNH, in order to provide an accurate pressure-based altitude reading. If the selected sea level pressure is too low, the altitude will read too low as well; if the pressure is too high, it will read too high. However, as I mentioned earlier, Cakung Airport had no way to transmit QNH when air traffic services were off duty, and there was no longer a procedure explaining how to use the Dili QNH for approaches to Baucau. The flight crew could still have used the Dili QNH simply by calling the Dili tower, who also could have explained why Baucau tower was not picking up, but the crew never attempted to do this. Instead, Dyatlov just told Shadrunov to set his altimeter using a QNH of 760 mm Hg (millimeters of mercury*), which is standard sea level pressure. Standard pressure is normally only used above a designated transition altitude, in order to ensure that all aircraft in upper-level airspace have their altimeters set to a common baseline. The actual local sea level pressure is only used when approaching an airport. But for obvious reasons, approaching an airport using the standard pressure setting when the actual QNH is unknown could be extremely dangerous, depending on the difference between the two.</p><blockquote>*Note: In the United States, inches of mercury are used for altimeter calibration. Millimeters of mercury are used in China and the former Soviet Union, while the rest of the world uses hectopascals.</blockquote><p>However, in the former Soviet Union, approaches were historically made with reference not to QNH, but to QFE. QFE is the actual local pressure at the field elevation, whereas QNH is the sea level pressure at the field, even if the field is not at sea level. In practical terms, this means that if the field elevation is 1,000 feet and you have a barometric altimeter set according to QNH, the altimeter will read 1,000 feet when you’re on the runway; and if your altimeter is set according to QFE, it will read zero when you’re on the runway. And while Russia today is transitioning away from the use of QFE, in 2003 it was all these pilots knew. So Dyatlov used the field elevation for Cakung Airport in the Jeppesen charts, which was 1,729 feet (527 m), corresponding to sea level pressure minus 62 hectopascals, and converted this value to millimeters of mercury, arriving at a QFE setting of 714 mm Hg.</p><p>After the accident, investigators estimated that the real QNH for Cakung on the day of the flight was about 758 mm Hg, for a real QFE of 712, which meant that the pilots’ barometric altimeters would have read about 60 feet (18.3 m) too high. Survey results showed that the runway elevation shown on the Jeppesen chart was also 26 feet too high, but this would have had no real effect. So, taken in total, Dyatlov’s estimate wasn’t a bad one, and 60 feet would have seemed unlikely to mean the difference between life and death. But flying is a margins game, and theirs were being slowly and steadily eroded.</p><p>Having made these selections, the crew continued their descent with reference to standard barometric pressure, reaching 10,000 feet at 14:49. Below 10,000 feet in Timor-Leste airspace, the Timor Common Low frequency should be used to broadcast position and intentions, but the crew didn’t tune in to this channel either.</p><p>Less than a minute later, the flight also descended through 9,300 feet, which was the 10-nautical-mile MSA for Baucau. Further descent to 4,500 feet was only permitted if they were on the Ambon-Baucau airway, but the flight data shows that they were never actually tracking directly toward the Baucau NDB, and thus were never on the airway, likely because they were navigating with reference to GPS instead. It should also be noted that the MSA wouldn’t apply if they were in visual meteorological conditions (VMC), but witnesses in the Baucau area reported that the conditions were overcast with a cloud base at about 1,000 feet (305 m) above ground level and a visibility of only about 1,500 meters. Therefore, the MSA should have applied.</p><p>The fact that the crew were not navigating with respect to the NDB is significant in light of what happened next. It is known that navigator Dyatlov was actually providing heading and position data to Captain Shadrunov based on the readout from a Bendix/King KLN-90B GPS navigation system, which was installed at the navigator’s station as an aftermarket product. The system was not described in the flight manual, and it could only display in feet and nautical miles; it was not capable of displaying distances in terms of meters and kilometers. That meant that Dyatlov had to manually convert the GPS readouts before passing them to Shadrunov, whose instruments displayed metric units.</p><p>Over the next two minutes, while Dyatlov provided their distance to run and lateral offset from the runway, Shadrunov continued the descent through the NDB approach commencement altitude of 5,500 feet, then through the 4,500-foot LSALT for the Ambon-Baucau airway, again without any comment from any of the crewmembers, continuing the pattern observed in the briefing. Evidently they had no intention to observe any of the minimum altitudes.</p><p>In the background, First Officer Matvienko made his 25th and final unsuccessful effort to hail Baucau Tower.</p><p>As they neared the airport, still flying approximately south-southwest and maintaining a height of 400 meters (1,312 ft) above field elevation, Dyatlov waited for his GPS to show that they were crossing the runway centerline. “We’ll check how we will path over the runway using my data,” he said at 14:53, after which he added, “We’ll take into consideration (unintelligible) on GPS.”</p><p>Moments later, Dyatlov tried calling the tower himself, and no doubt to the crew’s astonishment, this time someone replied. An off-duty United Nations ATS officer who happened to be passing the ATS station heard the navigator’s call and picked up the radio, into which he said, “Baucau traffic services, at your discretion for landing.”</p><p>Dyatlov acknowledged that they would descend and land at their discretion, then signed off. None of the pilots suggested asking for the current QNH or QFE setting, nor did they ask for any weather information, such as visibility or cloud ceiling. The flight crew would have had no knowledge of the weather conditions at the field because the Timor-Leste government had issued neither an aerodrome forecast nor a METAR (aviation routine weather report) for Baucau, so the only way to find out the current conditions was to ask someone on the ground. Unfortunately, this opportunity was missed.</p><p>Just after 14:54, the flight reached the extended centerline of the runway as displayed on Dyatlov’s GPS, so he said “to the left 135 degrees,” referring to the runway heading shown on the Jeppesen chart, and Captain Shadrunov announced, “Turning.” However, by this point it was too late to avoid overshooting the depicted centerline, so the plane swung out almost 2 km right of the intended course. Dyatlov compensated by instructing Shadrunov to turn left further, to heading 105, in order to return to the centerline.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1wjK0wHlbK7Jc-Jk56BVcA.png" /><figcaption>Overview of the initial test approach to Baucau. Apologies for the low resolution; this was the only resolution available in the ATSB report. (ATSB)</figcaption></figure><p>Completing this turn, Shadrunov declared “on heading,” and Dyatlov announced they were 1.5 km laterally from the centerline with a distance to run of 3 km. Moments later he added, “1,000 meters laterally, distance is 3, to the right on landing.” Shadrunov replied “turning,” beginning a right turn back to heading 135, but before he could complete the turn, the runway suddenly appeared through the mist, almost directly beneath them. On the ground below, a witness took a photograph of the Il-76 passing overhead, its ghostly form partly shrouded in clouds, testifying to the poor conditions that hid the runway from the crew until the last moment.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ZAXDemA_54HnXWYtz6R_ZA.png" /><figcaption>A witness’s photo of RDPL-34141 overflying the aerodrome during the test approach. (ATSB)</figcaption></figure><p>Considering that Dyatlov had just announced 3 km to run, the abrupt appearance of the runway was completely unexpected, and required investigation.</p><p>It turns out that Dyatlov had programmed the runway threshold and centerline into the GPS based on the coordinates and runway heading provided on the Jeppesen chart. As I already mentioned, the runway heading on the chart was wrong — it was 139 degrees, not 135 — but the airport position itself was even more seriously askew. The coordinates on the chart put the runway 2.38 km (1.29 NM) southeast of its actual position, which meant that for a flight coming in from the northwest, the runway would have appeared beneath the airplane 2.38 km earlier than the crew was expecting.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dliyFEbwZ1UpJJkh02ZD2A.png" /><figcaption>The actual position of the runway relative to the NDB, vs. the Jeppesen position. (ATSB)</figcaption></figure><p>One aspect worth noting is that the chart showed the location of the NDB correctly. The depiction of the airport environs had the NDB positioned northwest of the runway, when in fact it was abeam the runway’s midpoint, but as I just said, it was the runway position that was wrong, not the NDB. Therefore, if the pilots had been navigating with reference to the NDB, as envisioned by the runway 14 NDB approach procedure, the incorrect airport coordinates would have been irrelevant.</p><p>Here I want to stop and explain what these pilots were actually doing, in context. While this was only a test approach, it was still an approach. Regardless of whether the pilots intend to land, an instrument flight rules (IFR) flight through instrument meteorological conditions (IMC) in uncontrolled airspace <em>must</em> adhere at all times to either the sector minimum altitude or a published instrument procedure. There are very good reasons why pilots aren’t supposed to go rambling all over the place below the MSA in IMC like they own the airspace.</p><p>However, throughout the late 1990s and 2000s, as GPS technology became more accurate, some flight crews who operated into poorly equipped or underserved airports began to fly so-called “user-generated GPS approaches.”</p><p>Of course, GPS approaches are real and they’re used all the time; there are several types (RNAV, RNP, etc.), but the basic idea behind all of them is that the approach is flown with reference to a set of published GPS coordinates instead of or in addition to radio navigational aids. Today, underequipped airports commonly have a published RNAV or RNP approach procedure because these approach types don’t require any ground infrastructure. In 2003, however, this was less common.</p><p>A published GPS-based approach has been thoroughly reviewed and tested in order to ensure that it provides adequate terrain separation, possesses appropriate minimums, and so on. Such an approach will also be included in digital databases to allow aircraft equipped with a flight management system to fly the approach automatically. This is also the case for all types of instrument approaches, but GPS approaches are unique in that it’s possible for the flight crew to invent a new GPS approach from whole cloth, because there’s nothing stopping a pilot from plopping down a bunch of GPS waypoints leading up to the runway and then attempting to follow them. Several accidents have been attributed to these unapproved techniques, especially during the period before RNAV/RNP approaches became universal. For another example of a user-generated approach created by generating waypoints using a flight management system, see <a href="https://medium.com/@admiralcloudberg/an-unanswered-call-the-crash-of-airblue-flight-202-2b39aecfa7a7">my 2020 article on Airblue flight 202</a>.*</p><blockquote>*Note: This article is on the older side and my research and general knowledge may not have been as good as they are today. I have not gone back to review it for errors or bad takes.</blockquote><p>In this case, Dyatlov was creating a user-generated GPS approach without the benefit of a flight management system by simply calling out the lateral offset and distance to run between<em> </em>the GPS position of the aircraft and the GPS position of the runway, which as we now know was incorrect. And that’s precisely why you don’t make up your own approach procedures.</p><p>At this point, the pilots could have decided to just fly the published NDB approach, which would have resulted in a safe landing. They could even have cross-checked the visual position of the runway against the position of the NDB as indicated on their ADFs, observed that the two were co-located, and then generated a new GPS approach with reference to the NDB, which still would have been a massive violation of the very concept of standard operating procedures, but would probably have also resulted in a safe landing. But instead, the pilots did neither of those things.</p><p>Having established that the runway position was not where he thought it was, Dyatlov told Shadrunov to roll out on the assumed runway heading of 135 degrees and climb to a height of 500 meters (1,640 ft) above the field elevation (about 3,350 ft or 1,021 m above sea level) in order to make another approach. This was not the published missed approach procedure for runway 14, which was to fly out on the approach heading of 146˚, climb to 2,800 ft above sea level (853 m), then turn left back to the NDB while climbing to the initial approach altitude of 5,500 ft (1,676 m). The correct missed approach procedure had been part of Shadrunov’s approach briefing, but he casually disregarded it now.</p><p>After reaching 500 meters, Shadrunov began a left turn to reverse course and try again. As they passed about 5 kilometers abeam the runway on the downwind leg, Dyatlov asked whether the pilots could see the runway to their left, and Shadrunov replied that he could not.</p><p>“What is lateral?” Shadrunov asked.</p><p>“Lateral is 4.8 [kilometers],” Dyatlov replied. Shadrunov then instructed the flight engineer to extend the landing gear, flaps, and slats in anticipation of an approach.</p><p>At 14:58, Dyatlov said “Let’s [go] to the left,” and Shadrunov turned left onto the base leg of the circuit. As he did so, Dyatlov informed them that they were 8 kilometers radial distance from the runway, and 4 kilometers lateral distance. He then guided Shadrunov through the turn, telling him when to turn and when to stop, while calling out their distance every kilometer.</p><p>At a reported distance of 7 km, Shadrunov began a step-down descent to a height of 300 meters; however, their actual distance from the threshold at this point was less than 5 kilometers. With this discrepancy still uncorrected, they rolled onto final approach and aligned with the supposed runway centerline of 135 degrees. But shortly after Dyatlov called out 4 kilometers, First Officer Matvienko apparently spotted the runway through the fog and announced, “threshold.”</p><p>“Threshold,” Shadrunov repeated. “We already passed [the] runway.”</p><p>At this point, they had not yet overflown the runway, which still lay a little over a kilometer ahead of them. Nevertheless, it was obvious that they were too high to effect a landing.</p><p>“That means the data was not right, go to the left,” Dyatlov instructed. He then hastily added, “I took 4 kilometers correction.”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*JPTIxB-rKIYzaE2XtWio9g.png" /><figcaption>Events of the first approach attempt and second go-around. (ATSB)</figcaption></figure><p>What Dyatlov meant here was that he was now changing the coordinates of the runway on his GPS device, moving them 4 kilometers to the north to account for the apparent discrepancy in the runway position. However, as I mentioned earlier, the actual runway position was only 2.38 km from the erroneous position on the Jeppesen chart, so 4 km was an overcorrection. Investigators believed that Dyatlov interpreted Shadrunov’s statement, “We already passed the runway,” to mean that they were over the runway at that time, when in fact the threshold was still ahead of them. This statement was made at a distance between 3 and 4 km from the Jeppesen runway position, thus leading Dyatlov to apply a 4 km correction. However, it’s not entirely clear to me why Dyatlov, who we know was seated in the navigator’s station (because that’s where the GPS was installed), did not himself observe that the runway still lay more than 1,500 meters ahead. Ensconced in a bubble of windows, he should have had an excellent view ahead and below the aircraft.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4viry0vRRBI6EREISLX8ng.png" /><figcaption>The same witness’s photo of the Il-76 during the second overflight of the airport, following the first approach attempt. (ATSB)</figcaption></figure><p>In any case, having clearly missed the runway, Shadrunov initiated another missed approach, instructing Flight Engineer Busygin to retract the gear and flaps again. As he climbed again to a height of 500 meters, he said, addressing Dyatlov by his familiar name, “Sasha, that threshold was the runway on which we should land.”</p><p>“I understand,” Dyatlov replied.</p><p>“We approached a little bit actively,” Shadrunov added.</p><p>“So, I understood to minus 3 kilometers approximately, even 4, we’ll descend by stepped,” Dyatlov explained. This time, with his corrected runway position estimate, he was confident they could descend early enough to land.</p><p>The cockpit was largely quiet as Shadrunov steered the plane onto the downwind leg, broken only by his instructions to put the gear and flaps back down. This continued until about 15:03, when Dyatlov said, “On to left turn and 400 meters maintaining.” A few seconds later he added, “We can descend to 200.”</p><p>“OK, descending,” Shadrunov acknowledged.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8-Nu59EKUELb0SB7ettXAQ.png" /><figcaption>Events of the second approach attempt. (ATSB)</figcaption></figure><p>Continuing through the base turn and onto final, Dyatlov regularly provided GPS position information.</p><p>“Lateral 2, distance is 6 kilometers, Descending 250 meters.”</p><p>“Lateral 600 meters, distance is 5…”</p><p>“Above [by] 60 meters.”</p><p>“Flaps and slats,” Shadrunov called out.</p><p>“Turning on landing heading,” Dyatlov instructed, and Shadrunov began the final turn onto heading 135. This heading was still erroneous, with the proper approach heading being 146 and the runway heading being 139, but none of the pilots had observed this discrepancy so far.</p><p>“Now we are crossing landing heading, distance is… ah… in 4 kilometers,” Dyatlov continued.</p><p>Shadrunov slightly overshot the landing course to the right and began to correct. “On the right 200 meters, distance is 3,” Dyatlov called out. “Have this heading, distance is 3.5.”</p><p>“On radio altimeter 300 we have, continue descending.”</p><p>“Distance now is 3.”</p><p>“Distance is 2 kilometers.”</p><p>“We are flying above again,” he admonished.</p><p>If we imagine a normal glide path to the location where Dyatlov believed the threshold to be, then they should have been at only 100 meters above the field by this point, while their actual height was about 200 meters. However, the minimum descent height for the NDB approach was 162 meters, so any further descent below this altitude shouldn’t have been attempted until the runway was in sight, which it was not. This fact was not mentioned by the crew, who had made no mention of any minimum altitudes at any point during the flight, nor had they devised any minimum descent height for their improvised GPS approach. And taking into account Dyatlov’s overcorrection, which placed his imagined threshold 1.62 km (0.9 NM) short of its actual location, the puzzle pieces of disaster were starting to fall into place.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*nsl3fU-VurMZQuwlPccwxw.png" /><figcaption>Terrain view of RDPL-34141’s flight path leading up to the accident. (ATSB)</figcaption></figure><p>Then, in response to Dyatlov’s report that they were too high, Captain Shadrunov increased the rate of descent to 18 meters per second (3,543 feet per minute), which was extremely excessive in such close proximity to the ground — so much so that it’s hard to believe he chose this descent rate intentionally. Investigators concluded that he probably misjudged his input and then failed to detect the error because his attention was focused outside the aircraft in an effort to spot the runway, and not inside at his instruments.</p><p>This is a classic mistake that has killed numerous flight crews throughout history, and it stems from the very human desire to see where we’re going and to get to the destination, but it’s contrary to the way pilots are trained to fly instrument approaches. Although there exist various standard distributions of tasks during a non-precision approach, under the “traditional*” arrangement it is expected that the pilot flying the aircraft will not search for visual reference to the runway until the pilot monitoring calls “visual.” The pilot monitoring is therefore responsible for acquiring visual reference in addition to monitoring the instruments, while the pilot flying exclusively uses the instruments to control the flight path. This ensures that the transition from instrument to visual flying doesn’t occur before a visual reference has actually been established.</p><blockquote>*Note: “Traditional” is contrasted here with the “monitored approach” concept, which is increasingly popular around the world. Under the monitored approach concept, the pilot monitoring takes over as pilot flying and lands the airplane upon acquiring visual reference. Scientific studies show that this concept may reduce the risk of transitioning to visual flight prematurely, continuing an unsafe approach, or making a go-around decision below the decision height.</blockquote><p>Regardless, once Captain Shadrunov initiated the excessively steep descent, First Officer Matvienko should have monitored the instruments and called out the deviation, allowing Shadrunov to correct. Unfortunately, this didn’t occur, and we don’t know the exact reason why — but it has to be kept in mind that this error occurred in a context in which Shadrunov and Dyatlov were intentionally violating multiple standard operating procedures, rendering it unclear which violations should be called to their attention. Ideally, all violations should be called out, even if intentional, but in an operating context where SOPs are barely even a suggestion, that kind of behavior is difficult to expect. Additionally, Matvienko was a passive observer to the entire flight thus far, and it does not seem like he was empowered to comment on the captain’s piloting, nor did he necessarily feel that that was his role. With a Russian aviation background in 2003, it was unlikely that any of the pilots had received much training on crew resource management, which is explicitly intended to alleviate this kind of imbalance.</p><p>Therefore, because of Dyatlov’s mistaken runway coordinates, they were descending toward a point that was 1.62 km short of the actual runway, and now Shadrunov was descending so quickly that they would have little time to react when they broke out of the clouds and realized the error. Disaster was now almost inevitable.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TbfP5YgDSv4w8uo6tIYskw.png" /><figcaption>The vertical flight path during the final minutes of the flight. (ATSB)</figcaption></figure><p>At this point, Captain Shadrunov might still have realized his mistake if not for a series of confounding factors that finally sealed the fate of RDPL-34141 and her crew.</p><p>The first of these was that the weather conditions in the approach area were markedly worsening, with witnesses reporting fog or mist with a forward visibility of only 200 to 300 meters. This would have prevented Shadrunov from recognizing their excessive descent rate by using visual references.</p><p>The next factor was a misunderstanding on the flight deck. When Dyatlov told him to increase the descent rate, Shadrunov declared, “increased,” but Flight Engineer Busygin thought he was commanding an increase in engine power. This might have been a sign that Busygin was aware of the situation and was anticipating a missed approach, priming him to expect a command to increase thrust, but we will never know for sure. If he had such concerns, he never voiced them.</p><p>In response to the perceived command, Busygin leaned forward and pushed the thrust levers toward go-around power, calling out “Increased.”</p><p>“Descending,” Dyatlov confirmed.</p><p>Within seconds, Shadrunov realized Busygin’s error and said, “No, I increased vertical speed.” He then grabbed the thrust levers and reduced power back to where it was before.</p><p>During those critical seconds, the aircraft descended through the MDH of 162 meters without comment from any of the crew. The distraction posed by the flight engineer’s erroneous thrust increase may have prevented Shadrunov from realizing that they were now flying too low.</p><p>It was at this moment that the third and final factor reared its ugly head. With the plane descending rapidly toward the ground, the flight path now met the activation criteria for the “sink rate” and “pull up” warnings from the Il-76’s ground proximity warning system, or GPWS — but no warning was heard.</p><p>Investigators examined a number of possible reasons for the conspicuous absence of this unmistakable warning. One early possibility was that the cockpit voice recorder simply hadn’t picked it up, because the Soviet CVR on the Il-76 only recorded audio when a crewmember spoke over the cockpit intercom, and for 15 seconds afterward. The CVR didn’t have a cockpit area microphone to continuously capture ambient sounds, so if the GPWS had sounded more than 15 seconds since the last statement by a pilot, it would not have been captured. However, while this was a poor design that didn’t meet ICAO standards, it was not the reason for the missing warning, because there were no gaps in conversation longer than 15 seconds during the final approach, and thus no audio during this phase could be missing.</p><p>Another possibility was a malfunction of the radio altimeter, from which the GPWS extracted the aircraft’s height above terrain. The flight data recorder did not record the aircraft’s radio altitude, and a note reading “no altitude from RALT” was found attached to the FDR cassette. However, statements by the pilots indicate that they were able to read the radio altimeter indications during the flight, so this was ruled to be a malfunction of the FDR itself, and not the altimeter.</p><p>With these possibilities ruled out, the only real remaining explanation for the missing warning was a malfunction of the GPWS unit itself. However, the unit was never recovered, and the cause of the malfunction, if there was one, remains unknown.</p><p>Had the warning sounded, Captain Shadrunov would have had about 8.7 seconds to avoid ground impact. This isn’t a lot, and the plane might have crashed anyway unless he performed a very aggressive escape maneuver — but without the warning, there was no hope whatsoever.</p><p>It’s also worth pointing out that if the procedure on the Il-76 had been to set the captain’s radio altimeter bug to the MDH, and had this procedure been followed, then they would have received a “below preselected altitude” alert at 162 meters. This alert may have increased the pilots’ situational awareness as to their vertical profile. However, as you hopefully recall, the actual procedure was to set the bug to 60 meters, and even this rather useless step was never performed. Had the alert gone off at 60 meters, with the plane descending at 18 meters per second, there would not have been adequate time to avoid ground impact, but as we will soon see, the consequences may have been somewhat reduced.</p><p>Unfortunately, none of this occurred, and disaster was assured.</p><p>During the final seconds, the CVR recorded Shadrunov calling out, “Speed is 250, 250,” followed by Dyatlov announcing, “Descending, distance is about 2.”</p><p>“OK,” Shadrunov confirmed.</p><p>Suddenly, the plane broke out of the clouds, and the crew spotted the ground — but it was too late. Just under three seconds from impact, First Officer Matvienko shouted, “Ach, increase altitude!”</p><p>Both pilots immediately pulled back on their controls to climb, but no one increased thrust, hampering the escape attempt. Matvienko announced, “Recovering,” but his was the last word recorded by the CVR.</p><p>At 15:05 and 34 seconds, RDPL-34141 touched down in the grass 1,877 meters short of runway 14. Within a split second of wheels-down, the left wing struck several large trees and the landing gear impacted a fence, causing severe damage to both. The huge jet yawed and rolled violently to the left as the left wing folded upward and the airplane turned inverted, sliding upside down across a field. The entire forward fuselage, including the cockpit, then slammed headlong into a serrated limestone rock outcropping, which sliced through the plane like an unholy cheese grater, rendering aircraft and occupants alike into small, confetti-like fragments.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*kK3X1xN3EIsY5BUbx1m3vA.png" /><figcaption>The partially constructed house struck by the airplane during the impact sequence. (ATSB)</figcaption></figure><p>As the disintegrating airplane continued forward, fire billowed from its riven fuel tanks, and the inverted right wing clipped a partially constructed house, whose owner was inside at the time but miraculously escaped injury. The remaining fuselage then broke into several pieces, which tumbled to a halt a few dozen meters further on, surrounded by fire.</p><p>At Cakung Airport, UN personnel witnessed a huge explosion in the fog short of the runway, and firefighting vehicles were dispatched to the site as quickly as possible, arriving within five minutes of the crash. But aside from tamping down the flames, there was little they could do. All six crewmembers had perished on impact, and in fact so horrific was the destruction of the cockpit area that some of the victims were never positively identified.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*24OHFwZ3ZnZ0LqluABSD_A.png" /><figcaption>Smoke rises beyond the Baucau runway, minutes after the accident. (ATSB)</figcaption></figure><p>In many war-torn countries, like present day Sudan, the crash of a non-scheduled cargo flight run by a dubious operator would never be investigated at all. But Timor-Leste was no longer a war zone, and with the United Nations still more or less running the show, the diplomatic gears immediately started to turn. Within hours of the accident, Timor-Leste’s fledgling Ministry of Transport, Communications, and Public Works sent a request for help to the Australian Transport Safety Bureau, which sent a team of air crash investigators to Baucau to gather the evidence and determine the cause. The investigation was technically run under the auspices of the Timor-Leste Ministry of Transport, but since the country did not have any air crash investigators, the investigation was entirely conducted by Australian experts. Timor-Leste’s willingness to ask for help and Australia’s commitment to openness ensured that this investigation was transparent and that its results were released to the public. Without that dedication this article could not have been written.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/500/0*jIY89RIEQNRHDGwR.jpg" /><figcaption>An aerial view of the entire wreckage trail. (Cameo Pourghannad)</figcaption></figure><p>The investigation proved to be a challenge unlike any other that the Australian investigators had faced. The aircraft involved was enormous, the investigation team was abnormally small, and no one on it knew the first thing about the Il-76, beyond what was available on the internet. The investigators had to familiarize themselves with detailed Il-76 design specifications and operating procedures provided by the aircraft’s owners and operator, followed by a tour of a real Il-76, before they could even begin to piece together what went wrong. On top of this, the team also had to record and analyze a vast and complex wreckage field while operating out of a town that had almost no services, forcing the investigation to achieve full self-sufficiency in terms of basic needs like food and electricity.</p><p>Adding even further to the burden on the investigators was the complex ownership structure of the aircraft and the sheer number of countries involved. In a paper about the investigation written after the fact, Barter et al. plainly laid out this challenge: <em>“With the increasing use of charter aircraft registered in third world counties to transport cargo and passengers, combined with the large number of ex-Soviet Union aircraft and aircrew on the market, extraordinarily complex ownership and responsibility arrangements have developed which make the task of investigating accidents backgrounds for aircraft maintenance, flight crew compliance and who should join in the investigation, difficult.”</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fxZ6Q-08d3N23ZtAnHAfCw.png" /><figcaption>View of the wreckage site relative to the runway. (ATSB)</figcaption></figure><p>Nevertheless, the investigation was able to come to the technical conclusions I’ve already presented in this article, as well as providing the framework for my efforts to identify the companies involved, even though the final report did not name any of the companies.</p><p>The investigation also raised several points of analysis that I want to return to, in relation to both the background of the flight and the sequence of events itself.</p><p>Investigators concluded that while the major causes of RDPL-34141’s controlled flight into terrain included the flight crew’s decision to conduct a user-generated GPS approach and the captain’s inappropriate use of a high descent rate close to the ground, a number of other factors also narrowed the available margin of error and brought the risk of ground contact from likely to virtually certain. All of these factors are things I discussed in the preceding sections, but now I want to quantify what role they may have played, if any.</p><p>As you may recall, the captain had not set his radio altimeter bug to warn when descending below 60 meters; the crew was using an estimated altimeter setting that resulted in a barometric altitude reading that was 20 meters too high; and thrust was not increased during the go-around attempt. Had these errors not occurred, either individually or in concert, then the recovery attempt could have been started fractionally earlier and with greater efficiency, and the aircraft may have cleared the trees, fence, and rock outcropping before impacting the ground, possibly rendering the crash survivable for some or all of the occupants. These were tiny margins, little more than a rounding error, but as I said earlier, aviation safety is about margins. The truth is that these “rounding errors” stemmed from preventable procedural violations that might have cost crewmembers their lives.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*j1NKyOoJFyUYaFRFWVvPSw.png" /><figcaption>The accident site as seen from the opposite direction, looking north against the plane’s direction of travel. (ATSB)</figcaption></figure><p>At the same time, margins were also reduced by crew decision-making earlier in the flight. The decision not to ask Dili tower or the off-duty Baucau controller for the local barometric pressure and visibility decreased the pilots’ situational awareness and instrument accuracy, and their decision not to establish a minimum descent height for their improvised approach increased the risk of descending into terrain. The decision not to use the NDB to cross-check the GPS coordinates of the airport after discovering the incorrect Jeppesen data also prevented the crew from accurately judging the location of the runway.</p><p>After the accident, several changes were made to address deficiencies that increased the risk of landing at Baucau. The Jeppesen company withdrew its erroneous Baucau approach charts and ordered all copies to be destroyed; a NOTAM was issued warning flight crews that the Baucau QNH was not available outside of troop rotation days; Comoro Approach in Dili was established as the central point of coordination for all aircraft in Timor-Leste airspace; and the Timor-Leste CAD banned all non-UN aircraft from making instrument approaches to Baucau. But none of the deficiencies addressed by these changes would have mattered if the crew had followed the published approach procedure.</p><p>The reason why the crew did not fly the approved NDB approach was never determined. Although the NDB was found to be inoperative after the crash, evidence clearly showed that it was working during the accident flight. Alternatively, the crew might have been trying to save time, since the flight was 9 hours behind schedule and there might have been pressure not to increase that number. Colleagues of the accident crew who posted on the Russian pilots’ forum made unverifiable claims that the pilots on these types of flights were frequently expected to pay for the fuel cost of a diversion, among other coercive tactics intended to promote on-time arrivals. However, it seems to me that the flyover and circle actually performed by the crew would have saved little time, if any, relative to completing the approved procedure.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9HBKDCcXQU2x2Gv0WQJtKg.png" /><figcaption>The wreckage of the cockpit was found scattered over the sharp limestone rock outcropping. (ATSB)</figcaption></figure><p>One other possibility is that this crew flew user-generated GPS approaches habitually, perhaps because they saw GPS as more reliable than the navigational aids at remote airfields, or because it saved time at other airports, even if it didn’t at Baucau. But we will never know for sure.</p><p>The questionable decisions described above were made despite the fact that the flight had a very high base level of risk of controlled flight into terrain (CFIT), as measured by the Flight Safety Foundation’s CFIT risk calculator. This tool measures the risk of a CFIT event on a particular flight based on a number of quantifiable input values, and was used by the investigation into this accident to put the events into context. What they found was that even assuming the highest possible scores for the operator’s corporate culture, flight standards, and training, the base CFIT risk for this flight was high due to the lack of aids at the destination, the weather, and the terrain. Investigators pointed out that performing a simple risk analysis like this before a non-scheduled flight can help the crew make more cautious decisions.</p><p>In the actual event, the flight crew showed a deep-seated disregard for standard operating procedures that further increased the CFIT risk until an accident became inevitable. However, it’s worth pointing out that this kind of disregard was hardly unique to these individuals. While it can arise at any airline with a lax operating environment where safety and discipline are not given adequate attention, it was especially common among Russian overseas flight crews during the late Soviet and early post-Soviet periods, and I do think there’s more to it than just the company they worked for. Having studied this period of Russian history in an academic sociological context (<a href="https://drive.google.com/file/d/1OKuCmMYKc0NaHNLECWaF7S8hBveYt0NJ/view?usp=sharing">see my master’s thesis on the breakup of Aeroflot and its effect on Russian aviation safety</a>), there was a marked nihilistic streak that could be seen at all levels of society, including domestic aviation, but perhaps especially so among post-Soviet flight crews forced to seek work abroad. Accounts from people who worked in that environment and accident reports from the time period both highlight a profound sense of detachment, rooted in what I believe was a largely subconscious belief, among pilots and non-pilots alike, that they as individuals did not have real agency, and that if bad things happened to them, then that was just fate. And sometimes it was, but just as often in aviation, that very detachment creates the conditions for “fate” to deal a bad hand.</p><p>Today, this tendency has largely faded away, tied as it was to that particularly chaotic and desperate period of Russian history. But its mark is, in my opinion, visible in this accident. These pilots had families back home, they had decades of aviation experience, they were deeply familiar with the Il-76. They, like all pilots flying in the post-Soviet shadow industry, knew that what they were doing was inherently dangerous. Some, probably all, had lost colleagues in prior accidents. And yet they still allowed themselves to make unnecessarily risky decisions. And in the corners of the Russian-language internet where Russian overseas pilots gathered after the crash, the discussion was not about the causes of the tragedy, or how it could be avoided in the future — no, the consensus was “there but for the grace of god go I.”</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qni9G1aH4ID6mZUTmJfb4Q.png" /><figcaption>A closer view of the main wreckage of the fuselage, wings, and tail. (ATSB)</figcaption></figure><p>Although this mentality likely contributed to faulty decision-making, a significant part of the responsibility for the crew’s poor discipline necessarily arises from the operating environment created by the companies that employed them. However, the investigation was unable to meaningfully examine the company culture of the operator, probably because there was none to speak of. As far as I can tell, Euro-Asia Aviation was a paper company that was only ever intended to operate a few dozen flights, then disappear after a few months or a year; and as such its operational control over the accident flight would have been minimal.</p><p>Nevertheless, there are a few things that can be said about this topic. For instance, investigators did obtain the operations manual issued by Euro-Asia Aviation, which they found did not contain detailed instructions related to the SOPs for each phase of the flight, departure and approach briefings, altitude awareness, route familiarization, the stabilized approach concept, limitations on descent rate near the ground, weather conditions required to commence or continue an approach, crew workload management, or CFIT avoidance. The absence of SOPs in so many crucial areas no doubt hindered the flight crew’s ability to operate the aircraft in the safest possible manner.</p><p>The investigation also found that Laos’s ability to oversee the airline was virtually non-existent. Earlier in this article, I mentioned that the Laos DCA had not properly issued the flight crew with the licenses required by ICAO, nor had the country notified ICAO of any differences between local licensing rules and ICAO rules. But the report also noted that the Laos DCA didn’t have any personnel qualified to conduct flight tests or supervise flight test examiners as part of the process of certificating an aircraft or airline, and in fact the DCA’s entire Flight Operations and Inspection section had only one employee. There was no evidence that the Laos DCA had performed any operational inspections of Euro-Asia Aviation, nor was it clear whether such an inspection was even possible. An ICAO audit of Laos and follow-up audit in 2002 found that the country did not have a viable system of compliance or enforcement of aviation regulations.</p><p>In my opinion, Laos may have been selected as the country of registration for RDPL-34141 precisely because of its lack of capability. In fact, after all my research, I have come to believe that the ownership structure of this aircraft and its sister ship RDPL-34138 was specifically designed to shield the true owners from liability.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/500/0*qHrPDWNKWUMl_44x.jpg" /><figcaption>An engine from the Il-76 lies along the wreckage trail. (Cameo Pourghannad)</figcaption></figure><p>As I discussed earlier in this article, there exists a global shadow industry of fly-by-night cargo operators that engage in a mixture of legitimate business and criminal activities, including smuggling of valuable goods, human beings, and illegal arms. The heyday of this industry was arguably in the late 1990s and 2000s, in part due to the glut of ex-Soviet aircraft and air crews available during that period, but it still exists today, and the Il-76 is still its biggest workhorse — and its most dangerous. In fact, as many as four Il-76 cargo planes have been destroyed in crashes or combat in 2025 in Sudan alone.*</p><blockquote>*Give or take a few. Data is sketchy.</blockquote><p>The owners of these shadow aircraft usually broker deals under the table, only to distance themselves from the contract by means of a spider web of leases and sub-leases between short-lived “paper” airlines. Each airline only exists for a year or two, maybe a little less, maybe a little more. Where possible, the airlines are registered in countries that have lax registration requirements, little or no ability to monitor airline activities, and little or no public disclosure of company information. Laos is such a country, and during my research I found evidence that several large cargo transport aircraft were registered in Laos on behalf of obscure and short-lived companies during the early 2000s.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/410/0*LJeRvxSqKczvoRaU.jpg" /><figcaption>UN personnel examine the wreckage. (IASA)</figcaption></figure><p>In the case of RDPL-34141, the actions of the paper companies demonstrated how this setup could effectively shield the owners. The Sharjah-based owners leased the aircraft to Euro-Asia Aviation with the stipulation that the latter could not sub-lease the aircraft without the owner’s written permission, only for Euro-Asia Aviation to turn around and do exactly that, sub-leasing the aircraft to another paper airline from Cambodia, another flag of convenience, with the approval of the Laos DCA, just days after the original lease agreement was signed. However, because no <em>written</em> permission for the sub-lease occurred, when the plane crashed the buck stopped with Euro-Asia Aviation. Euro-Asia Aviation then in turn claimed that the Cambodian sub-lessee Astro Air had requested landing rights at Baucau without authorization, punting the responsibility even farther down the chain. As far as I can tell the investigators never spoke to anyone from Astro Air and I found no evidence of this company’s existence outside of the half dozen flights operated by RDPL-34141 in the month before the crash. In fact, that was probably the point.</p><p>In my opinion, one would not set up this kind of “unauthorized” lease and sub-lease unless the intention was to obscure the involvement of the aircraft’s owners. That’s not normally something that’s done as a precaution in case of an accident. It’s what you do if you’re worried that the plane will be caught carrying something illegal.</p><p>Now, as far as I can tell, there was nothing illegal on board RDPL-34141 when it crashed. I spoke to a UN pilot who visited the scene in the years after the crash and reported that the Timor Telecom equipment was still there, scattered about in the field, confirming that the cargo manifest accurately reflected at least the majority of the contents. Furthermore, there was no reason to smuggle arms into Timor-Leste in 2003 because the war was over and the country was still largely run by the United Nations. Timor-Leste is also not a notable producer or consumer of illegal goods.</p><p>My personal belief is therefore that the accident flight was a perfectly legal charter operated by a chain of companies that were also involved, or were planning to become involved, in illegal or gray-area contracts.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1000/0*a8PgzA_kg-vqLfYI.jpg" /><figcaption>A close-up view of one of the engines. (ATSB)</figcaption></figure><p>This wasn’t my first time researching the aviation shadow industry in the early 2000s. For <a href="https://www.youtube.com/watch?v=QDwtEIDEgS0&amp;pp=0gcJCSkKAYcqIYzv">our podcast episode on the 2003 crash of Union des Transportes Africains de Guinée (UTA) flight 141</a>, my cohosts and I dived into the history of that aircraft and found that not only was it possibly smuggling cash intended for Hezbollah, but that the aircraft owner, a Palestinian-American man named Imad Saba, ran a network of “paper airlines” out of his operational base in Sharjah, UAE. A paper describing Saba’s activities in the UAE identified him as the owner of East/West Cargo (later renamed Air West), which was believed to be part of the arms smuggling network of Viktor Bout, the notorious weapons dealer who inspired the film <em>Lord of War</em> starring Nicholas Cage. You might also remember him as the convicted arms trafficker that the US traded with Russia for basketball player Brittney Griner in December 2022. He was a prolific operator of paper airlines, a vast smuggling empire that he ran from his base in Sharjah until he was forced out in 2004.</p><p>Being aware of this background, and being aware that the owners of RDPL-34141 were also based in Sharjah, I set out to find whether there was any connection, no matter how tenuous, between this aircraft and the companies and individuals I identified during my research into UTA flight 141. And to my surprise, I actually found one. But first, I had to identify the true owner of the aircraft — the entity referred to in the accident report as the “Sharjah-based company.”</p><p>At first, I wasn’t sure whether it was possible to identify this company. Databases of aircraft operators and registrations were invaluable in confirming the names and histories of the other companies involved, but they don’t generally list an aircraft’s owner unless the owner is also the operator. But once again, it was the Russian pilots’ forum posts from 2003 that came in handy. Multiple commenters on that thread independently identified the pilots’ employer as something called Express Avia FZE, and since the accident report stated that the aircraft owner and the pilots’ employer were the same entity, I realized that this was probably the company I was looking for.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1000/0*WEgGJ2Msm4POLvdu.jpg" /><figcaption>Badly burnt wreckage from the Il-76, including the landing gear. (ATSB)</figcaption></figure><p>The title “FZE” identifies a company registered in a United Arab Emirates Free Trade Zone. The purpose of a free trade zone is to create a duty-free area to facilitate transit of goods, ease investment, and encourage foreign companies to operate locally. While free trade zones exist all over the world, the UAE free trade zones specifically offer a number of benefits to companies that register there, including but not limited to exemption from import and export taxes, full foreign ownership of the business, full repatriation of profits to the country of ownership, corporate tax exemptions for up to 50 years, no personal income tax, and various other forms of support. While many legitimate businesses are registered in UAE free trade zones, the European Union has also identified such zones as hotbeds of criminal activity, including <em>“tax evasion, laundering of stolen goods, and trafficking of people and illicit substances.”</em></p><p>Sharjah Airport lies within the Sharjah free trade zone, making it an ideal base for individuals operating gray-zone and illegal cargo operations. That’s precisely why Viktor Bout and Imad Saba were both based there at the time of the Timor-Leste accident. In fact, Richard Chichakli, the government-appointed head of the Sharjah free trade zone at the time of its founding in 1995, was an associate of Viktor Bout. He left that post in 1996, allegedly to become the chief financial officer for several of Bout’s paper airlines (an allegation that Chichakli denies).</p><p>By 2003, more than 160 cargo airlines and freight forwarders were based at Sharjah Airport. I found that Express Avia FZE, the company identified as the owner of RDPL-34141, was one of them. In fact, a UAE company registry still lists it as a Sharjah-registered company, along with a telephone number. As far as I can tell this is the only remaining internet presence of Express Avia FZE, if it ever had any.</p><p>I wasn’t able to find the individuals that owned Express Avia FZE, so that line of inquiry ended up proving only that the owners of the ill-fated aircraft were indeed based in the hive of scum and villainy that is the Sharjah FTZ. Instead, it was the aircraft registries that provided a more direct link.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wXTmD-3QNe2aGQ_mgx8hOg.png" /><figcaption>View of the initial impact point. (ATSB)</figcaption></figure><p>RDPL-34141’s sister aircraft was RDPL-34138, which appears to have been the only other aircraft ever operated by Euro-Asia Aviation. Records show that in July 2003, six months after the crash in Timor-Leste, Euro-Asia Aviation essentially disappeared off the map, and RDPL-34138 was re-registered in Sudan to none other than East/West Cargo, the Bout network airline allegedly owned by Imad Saba. A different Il-76 belonging to that airline later crashed near Khartoum while carrying “humanitarian aid” during the height of the Darfur genocide in 2005.</p><p>The truth is that a link of this type isn’t surprising; the only surprising aspect was that I, an amateur journalist at best, was able to find it. During this period, there was in Sharjah what Douglas Farah described in his book, <em>Merchant of Death</em>, as a <em>“cutthroat expatriate community of Russian air entrepreneurs, pilots, crewmen, and mechanics.”</em> All of these people knew each other, worked together, and competed against one another. So even if the owners of Express Avia FZE didn’t answer to Imad Saba and Viktor Bout, it’s virtually certain that they had some kind of working relationship, at least enough to facilitate the sale or lease of RDPL-34138.</p><p>Does this revelation change the way I feel about the pilots of RDPL-34141? The answer is, not necessarily. The fact that their employer was almost certainly involved in an illegal smuggling operation, about which they were almost assuredly aware, doesn’t change the simultaneous fact that this “cutthroat expatriate community” existed because there were few jobs for pilots in Russia. But even though Shadrunov and Dyatlov and Matvienko and all the others were probably there out of desperation, the knowledge that they were part of a labor network that was also being used to support civil wars and even genocides must loom large over their memory. The violence wasn’t their fault, but it is plausible that they tolerated it.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/600/0*vVglBp3RngalaW9l.jpg" /><figcaption>Investigators recover one of the black boxes from the wreckage of the Ilyushin’s tail section. (Loris Molent)</figcaption></figure><p>And yet, from an aviation safety perspective, that question doesn’t really matter. The crash didn’t happen because of the moral character of the pilots, which we are not in a position to fully judge. It happened because the entire industry within which they were operating did not and still does not prioritize safety, a disregard that likewise infected the flight crew as they made their fateful approach to Baucau. And how could safety ever be a priority, when the purpose of these airlines was to generate blood money? One starts to see why it’s easier to just not think about the shadow industry at all, like most respectable aviation experts. Still, I am drawn to these stories like a moth to a flame.</p><p>Standing upon the conclusion to this story, looking out across the panorama of what I have written, I have to conclude that maybe none of it matters. The lessons of this crash are ones the legitimate airline industry learned decades ago, and the shadow industry isn’t interested in learning, so why pretend that I wrote this for any reason other than my own insatiable desire to follow the rabbit hole all the way down? Or is that just the post-Soviet nihilist in me talking? Regardless, I hope that you, the reader, learned something, whether it was about aviation history, or Timor-Leste, or sketchy Russians. So I thank you for reading my 15,000-word treatise on a forgotten cargo plane crash from 2003, and may you never find yourself in that strange, lawless world, into which we are afforded only the occasional glimpse, illuminated on the walls of Plato’s Cave by the light of a burning aircraft.</p><p>_______________________________________________________________</p><p><em>You can also see my work on Petter Hornfeldt’s YouTube channel “Mentour Pilot,” where I’m employed as a script writer and researcher.</em></p><p><em>Don’t forget to listen to Controlled Pod Into Terrain, my podcast (with slides!), where I discuss aerospace disasters with my cohosts Ariadne and J! </em><a href="https://www.youtube.com/@ControlledPodIntoTerrain"><em>Check out our channel here</em></a><em>.</em></p><p>_______________________________________________________________</p><p><a href="https://www.reddit.com/r/AdmiralCloudberg/comments/1plzxco/dark_networks_the_2003_timorleste_il76_crash_and/?">Join the discussion of this article on Reddit</a></p><p><a href="https://www.patreon.com/Admiral_Cloudberg">Support me on Patreon</a> (Note: I do not earn money from views on Medium!)</p><p><a href="https://bsky.app/profile/kyracloudy.bsky.social">Follow me on Bluesky</a></p><p>Visit <a href="https://www.reddit.com/r/AdmiralCloudberg/">r/admiralcloudberg</a> to read and discuss over 260 similar articles</p><p><a href="https://docs.google.com/document/d/145fG2xTEBLmdnyDHqGoILoO3ES7yI9jym2BHTzSjhpI/edit?usp=sharing"><strong>Bibliography</strong></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=4e67ab377760" width="1" height="1" alt=""><hr><p><a href="https://medium.com/the-academic/dark-networks-the-2003-timor-leste-il-76-crash-and-the-global-air-cargo-shadow-industry-4e67ab377760">Dark Networks: The 2003 Timor-Leste Il-76 crash and the global air cargo shadow industry</a> was originally published in <a href="https://medium.com/the-academic">The Academic</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[My work on behalf of Mentour Pilot]]></title>
            <link>https://admiralcloudberg.medium.com/my-work-on-behalf-of-mentour-pilot-217c3d4a74bf?source=rss-e119a26506e3------2</link>
            <guid isPermaLink="false">https://medium.com/p/217c3d4a74bf</guid>
            <dc:creator><![CDATA[Admiral Cloudberg]]></dc:creator>
            <pubDate>Tue, 02 Dec 2025 05:38:41 GMT</pubDate>
            <atom:updated>2025-12-02T05:38:41.213Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zUEE-JNLKUPlnxmtJZmTpw.png" /><figcaption>That’s me on the left. Freeze frame — “You’re probably wondering how I ended up here.”</figcaption></figure><p>Many of you are aware that I’ve been working as a researcher and script writer for <a href="https://www.youtube.com/@MentourPilot">Mentour Pilot over on YouTube</a> since June 2024. However, I never formally announced this anywhere, and many readers are still unaware, so I thought I’d make a post drawing attention to that fact.</p><p>Petter Hornfeldt recruited me off the street, so to speak, because he was looking for people with writing talent and aviation knowledge to expand his team. Since then I’ve written almost 40% of the videos his channel has put out. You might have noticed my name in the opening credits, but you also might not have; they’re easy to miss and I realize a lot of readers don’t even know my real name. Keep an eye out for “Kyra Dempsey — Research and Script.”</p><p>Joining the Mentour Pilot team has brought me extraordinary new contacts and information sources, as well as financial stability to an extent that my independent work alone could not achieve, which has been great from my perspective. It has, however, slowed down the pace of new articles. There are similarly a variety of reasons why Controlled Pod Into Terrain hasn’t released an episode since January, but one of them is that I referred Ariadne to the Mentour team and now she works for them too.</p><p>Anyway, my point is that while I release maybe one article a month if I’m lucky, my pace of content production is actually up. For those who have been following my work but haven’t checked out Mentour Pilot, I highly recommend doing so, even if you only watch the videos I worked on. While I do try to emulate Petter Hornfeldt’s own style, the videos I write for him are still recognizably mine and uphold the same level of breadth, detail, and passion, and if you like my articles, then I highly recommend watching them. They provide a really cool glimpse of what it would be like if my articles were brought to life by a full-time team of simulator pilots and animators.</p><p>Feel free to ask me about the process, what it’s like to work with Petter, or anything else!</p><p>You can follow this Reddit post for a regularly updated list of all Mentour Pilot videos where I was the primary writer: <a href="https://www.reddit.com/r/AdmiralCloudberg/comments/1pc04s9/my_work_on_behalf_of_mentour_pilot/">https://www.reddit.com/r/AdmiralCloudberg/comments/1pc04s9/my_work_on_behalf_of_mentour_pilot/</a></p><p>— Kyra</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=217c3d4a74bf" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Four Minutes over Mexico: The crash of Mexicana flight 940]]></title>
            <link>https://admiralcloudberg.medium.com/four-minutes-over-mexico-the-crash-of-mexicana-flight-940-d71f213a47c6?source=rss-e119a26506e3------2</link>
            <guid isPermaLink="false">https://medium.com/p/d71f213a47c6</guid>
            <category><![CDATA[mexico]]></category>
            <category><![CDATA[technology]]></category>
            <category><![CDATA[flying]]></category>
            <category><![CDATA[aviation]]></category>
            <dc:creator><![CDATA[Admiral Cloudberg]]></dc:creator>
            <pubDate>Wed, 22 Oct 2025 20:23:11 GMT</pubDate>
            <atom:updated>2025-11-22T18:57:57.339Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*Gc2yrUSliOXda6HG.jpg" /><figcaption>The wreckage of flight 940’s vertical stabilizer, where it fell to earth after separating from the airplane. (Bureau of Aircraft Accidents Archives)</figcaption></figure><p>On the 31st of March 1986, Mexico’s worst air disaster unfolded over the mountains of Michoacán, as the crew of a Boeing 727 struggled to save the lives of their passengers following a violent explosion aboard the aircraft. But the desperate fight lasted only four minutes. As astonished witnesses watched the burning airliner streaking overhead, enormous flames trailing in its wake, the 727 suddenly snapped in half, its incandescent remnants plunging like a meteor into a rugged ravine. There were no survivors.</p><p>Despite speculation that a bomb had detonated in the cargo hold, extensive testing of fragments found 32 kilometers from the crash site revealed that the explosion and fire were accidental — the culmination of a series of missteps and failures. However, public knowledge of those missteps is scant. The final report contains no discussion of the systemic factors that contributed to the disaster and there are major gaps in the accident narrative as well, leaving readers guessing about exactly what took place and why. That’s not to say that the conclusions were wrong, but rather that they are incomplete, and while safety lessons were drawn from the findings, others may have been missed. What follows is my best attempt to piece together what happened in the days and minutes leading up to the crash of Mexicana de Aviación flight 940 — and to imagine what a more thorough investigation might have looked like.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/648/0*AvHmEa3BaiiL9mEW.jpg" /><figcaption>A 1986 English-language advertisement for Mexicana. (Vintage Airliners)</figcaption></figure><p>Founded in 1921, Compañia Mexicana de Aviación, or just Mexicana for short, was the first airline in Mexico, and until its bankruptcy in 2010, it was the oldest continuously operating airline in North America. For much of that period, Mexicana was Mexico’s flag carrier and the primary competitor of the country’s current flag carrier, Aeroméxico. Mexicana was both state-owned and privately owned at various points throughout its existence; at the time of this story, it was the former.</p><p>In 1986, Mexicana’s fleet utilized McDonnell Douglas DC-10s for long haul services and Boeing 727–200s on short and medium-haul routes. Its fleet of 51 727–200s made it the largest operator of that type outside the United States.</p><p>When Mexicana began operating the 727 in 1966, the aircraft type had been in service for only two years and was still considered state-of-the-art; but by the time the airline retired its last 727 in 2003, the type had been out of production for almost 20 years and no longer met the noise and fuel efficiency requirements established by most countries and airlines. Therefore, as we dive into some of the systems that this airplane was and was not equipped with, the fact that it was 1960s technology should be kept in mind.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/800/0*illrQ64ZztX6VzKy" /><figcaption>XA-MEM, the aircraft involved in the accident, pictured in Puerto Vallarta in 1984. (George Gayuski)</figcaption></figure><p>This story involves a Boeing 727–200 with registration XA-MEM, which was built in March of 1981 and had completed around 10,000 flights for Mexicana when it arrived at Chicago’s O’Hare International Airport on the 30th of March, 1986. The flight had been uneventful, but during the landing rollout the crew noticed that the brakes were operating unevenly, and something seemed to be wrong with the right main gear brakes in particular. In the technical log, the pilot wrote, <em>“frenos disparejos, el derecho tiene aire”</em> (uneven brakes, the right one has air”). This presumably means that the brake felt spongy or took too long to engage, which can be caused by air in the brake lines.</p><p>The Boeing 727 is notable for having a particularly powerful braking system, at least relative to other aircraft at the time. The 727 was designed to meet the specifications of several US airlines that wanted to operate it on medium-haul routes out of smaller airports with very short runways, some measuring 5,000 feet or less, and to be able to land with a high gross weight. For this purpose, the brakes were designed to be run hard, with expanded capacity and resilience, in the expectation that they would be used to their fullest extent repeatedly during a short time period. In addition, the 727 was also sold with an optional nose gear brake that would kick in if the pilots pressed hard enough on the pedals — although airlines reportedly found that this feature was unnecessary because the main gear brakes were so strong by themselves. The high brake capacity was especially useful during that time period, when airlines often ran train-like route structures with many<em> en route </em>stops, sometimes while tankering fuel in order to minimize turnaround times — a practice that demanded much from the brakes.</p><p>While XA-MEM was on the ground in Chicago, technicians addressed the log entry by performing a routine brake bleed. This process involves depressing the brake pedal to force the air out of the lines, then forcing new hydraulic fluid back in to replace the escaped air. It’s a normal part of brake maintenance and has to be performed at a certain interval even if the pilots don’t report air in the brakes. The final report quotes the technical log, in which the technicians wrote, “Brakes bled OK for service,” but doesn’t clarify whether the technicians bled all of the brakes, or just the right side. However, I would assume that if only one side was bled, then the note would have specified which side, so if I had to guess I would say they probably just bled them all.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/830/1*pUecTi5_NGri3xzIBs0raw.png" /><figcaption>An excerpt from a technical/promotional publication put out by Boeing ahead of the release of the 727 in 1963. (Boeing via Avialogs)</figcaption></figure><p>Subsequently, the aircraft was returned to service, and the next morning XA-MEM flew from Chicago back to Mexico City International Airport; the final report doesn’t say whether this was performed by the same crew or a new crew.</p><p>After arriving at 07:12, the flight crew wrote up a number of new items in the technical log, including “short brake assembly rod, wheel #2;” “120 feet difference between altimeters;” “fault [with] lever to lower rear stairs;” “pressure in hydraulic system B is 3,150 psi;” and “strong vibration from thrust levers 1 &amp; 2.” So let’s go through and consider what each of these items means.</p><p>Without a detailed diagram of the brake assembly, I don’t know exactly what was meant by the “brake assembly rod,” but it might have been a rod designed to wear down at the same rate as the brake pads in order to give an indication of overall wear. Technicians stated that they measured the rod and found its length to be within limits. With regard to the second item, the altimeter difference, technicians emptied the water traps for the static ports that measure ambient air pressure and instructed the next crew to monitor the altimeters during the next flight. The third item, the air stair lever fault, was deferred until the next day. And the fifth item, the thrust lever vibration, was checked out and no problem was found.</p><p>The fourth item is interesting with regard to this story because hydraulic system B normally powers the brakes on the 727. According to documentation for that aircraft, the normal pressure in hydraulic systems A and B should be between 2,800 and 3,100 psi, meaning that a reading of 3,150 psi is slightly too high — presumably that’s why the pilots wrote it up. Was this issue related to the brake bleed performed by the technicians in Chicago? The final report doesn’t say, and as far as I can tell, the matter was never officially investigated. I don’t have the expertise to make my own judgment either. All we know for sure is that the technicians in Mexico City also deferred this issue until the next day, meaning that whatever problem was causing a slightly elevated hydraulic B pressure remained unresolved during the accident flight.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*v4zjgOwAc3pMKyDWVqvmRw.png" /><figcaption>The approximate route of Mexicana flight 940. (Own work, map by Google, airplane image courtesy Golden Age Posters)</figcaption></figure><p>That trip was to be flight 940 from Mexico City to Los Angeles, California, with scheduled stops in Puerto Vallarta and Mazatlán on Mexico’s west coast. A total of 159 passengers boarded, most of whom were from Mexico, although the manifest also included either six or nine from the United States,* eight members of a single French family, two Canadians, and four Swedes, including a staff member at the Swedish embassy in Mexico, and her children.</p><blockquote>*Sources disagree on the number of US passengers.</blockquote><p>In addition to the 159 passengers, the flight also included a crew of eight, consisting of five flight attendants and three flight crew.</p><p>In command was 36-year-old Captain Carlos Alberto Guadarrama Sixtos, who had been flying for Mexicana since 1971 and had accumulated a total of 6,328 flight hours, almost all of which would have been on the 727, which he had flown since 1973.</p><p>Captain Guadarrama’s wife and two children were also on board the flight, reportedly taking advantage of Guadarrama’s scheduled layover in Los Angeles to visit Disneyland. His wife, Graciela Flores, was a former Mexicana flight attendant who had coincidentally survived Mexicana’s last major accident, when a Boeing 727 crashed short of the runway at Mexico City Airport in 1969, killing 27 of the 118 people on board. According to some news reports, Flores was thrown from the plane into muddy water, apparently uninjured; she then helped several passengers escape the airplane before leaving in search of help. She later left that job to start a family, but today she found herself once again aboard a Mexicana 727. I am aware of reports that she was sitting in the cockpit jump seat because the flight was overbooked, but I was unable to verify this.</p><p>In addition, the second pilot was 34-year-old First Officer Philip Louis Piaget Rhorer, who had been flying the Boeing 727 for Mexicana since 1980 and had 1,769 total hours. And finally, rounding out the crew was 29-year-old Flight Engineer Angel Carlos Peñasco Espinoza, who had been working for Mexicana since 1982 and had 1,142 total hours.</p><p>◊◊◊</p><p>After completing all pre-flight checks and securing the aircraft, flight 940 pushed back and taxied to the runway. During taxi, Captain Guadarrama made a comment about the aircraft feeling “heavy” or “tied down,” although the final report omits the exact wording he used. In any case, this would become the first sign of trouble for this particularly troublesome flight.</p><p>Apparently without worrying too much about the strange sensation, Guadarrama taxied his aircraft into position on the runway at Mexico City and commenced the takeoff roll, departing at 08:50 local time. But much like the taxi phase, the takeoff was not entirely normal. In fact, Guadarrama soon commented to First Officer Piaget that the aircraft “felt heavy” and that they would have to “apply more power” in order to take off. Indeed, the acceleration was exceptionally slow, and even after pushing the engines forward to maximum power, it took 11 seconds longer than expected for flight 940 to become airborne — which is, relatively speaking, an eternity.</p><p>This probably would have struck the pilots as odd, because there was no obvious reason why this should have been the case. Although takeoff performance can be negatively affected by high density altitude and high temperatures, the temperature in Mexico City that morning was only 8˚C (46˚F), so even at the airport’s rather high elevation of 2,230 meters (7,316 ft), performance shouldn’t have been an issue. The investigation also later confirmed that the aircraft’s weight was correctly calculated and was 6,000 kg (13,200 lbs) under the maximum takeoff weight for the conditions.</p><p>In fact, the real cause of the slow acceleration was eventually identified as a dragging brake on the left main landing gear.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IFN6lI0wSySijJu4G5_c8g.png" /><figcaption>A diagram of a 727 wheel brake. This diagram actually shows the brake on the nose wheel, but in terms of the basic components and their relative positions, it’s similar enough. (Boeing via Avialogs)</figcaption></figure><p>Like almost any vehicle, the 727’s main wheels are equipped with disc-type brakes featuring fixed discs, or <em>stators</em>, that are forced against corresponding <em>rotor </em>discs attached to the wheels, in order to bleed off energy via friction. This process converts the kinetic energy of the vehicle into heat, which is why brakes get hot — and aircraft brakes in particular can get <em>really</em> hot. In fact, ventilation efficiency is a major component of brake performance, and contemporary Boeing publications tied the 727’s high braking capacity to “better natural ventilation.” The 727’s brakes also feature multiple stators and multiple rotors arranged in an alternating pattern, allowing each brake assembly to act like several brakes on the same wheel, greatly increasing the system’s power and efficiency.</p><p>After the accident, investigators found the brake assemblies from the two left main landing gear wheels on XA-MEM and sent them to their US-based manufacturers for analysis. That analysis found that the №2 brake assembly, located on the inboard wheel, had not been subject to temperatures exceeding those expected during normal operation. But the №1 brake assembly on the outboard left wheel was a different story. On this brake, a significant portion of the carrier and lining that hold the stators in place relative to the rotors was found to have melted and adhered to the faces of the rotors. The manufacturer, B. F. Goodrich, estimated that the temperature of the entire brake assembly must have been between 1,200 and 1,600˚F (650–870˚C) in order to melt the stator carrier and lining in such a wholesale manner. This was well beyond the temperature range encountered in normal operation.</p><p>However, such temperatures could have been achieved if the №1 brake was engaged throughout flight 940’s taxi and takeoff roll. If so, then more energy would have been required to move the airplane and bring it up to takeoff speed — and that extra energy would have gone directly into heating the brake assembly. A stuck brake would also have explained why the plane felt “tied down” during taxi and why its acceleration was abnormally slow.</p><p>Unfortunately, the investigation did not attempt to determine why this brake became stuck, or if it did, then this information was not included in the final report. The analysis by B. F. Goodrich did discover some unspecified damage inside the №1 brake debooster, which reduces hydraulic pressure when the brake stops being applied, but the company was unable to establish whether this damage occurred before or after the accident. If any further effort to determine the cause had been attempted but was unsuccessful, the report would normally say that the reason for the dragging brake “could not be determined,” but such language is also absent. The topic simply isn’t addressed, and the write-ups in the technical log and their corrective actions are never mentioned again in the final report.</p><p>Now is when I would love to say, “But through weeks of research, I was able to figure out what happened” — but I can’t, because I still don’t know. I have no way to determine whether the stuck brake was connected to the brake bleed work, or to the elevated Hydraulic B pressure, or anything else that I’ve shared with you up to this point, because that’s supposed to be the investigators’ job. I can dig through manuals, I can talk to experts, I can even do math sometimes, but I can’t do forensic analysis of aircraft parts or piece together maintenance timelines that were never made publicly available.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/776/1*3fJgXMNOgnOX4ynaui8Xng.png" /><figcaption>An overview of the 727’s landing gear. (Boeing via Avialogs)</figcaption></figure><p>Although I do think the stuck brake was probably related in some way to the recent maintenance, the available information doesn’t make it possible to guess whether that maintenance caused the problem, made it worse, or just failed to solve a problem that was already present, such as a fault with the debooster.</p><p>After the accident, media reported that the union representing Mexicana mechanics and ground crew “had complained [that] the airline’s planes were poorly maintained” (UPI), but a spokesman for the union denied that his organization had made any such statement.</p><p>If this investigation had been committed to chasing every lead, then not only would we know whether this brake was maintained correctly, but a lot might have been learned about Mexicana’s safety culture as a whole, which could have helped Mexicana become a safer airline and helped other airlines maintain their 727s more effectively. But that didn’t happen, and that’s the opportunity cost that comes with a narrow or amateurish investigation. Obviously it’s all water under the bridge now, since the last 40 years have seen the retirement of virtually all 727s and the bankruptcy of Mexicana de Aviación, but it would have been useful at the time.</p><p>◊◊◊</p><p>Returning to that crisp morning in Mexico City, as flight 940 rumbled toward the end of the runway, First Officer Piaget called “V1” and then “rotate,” and Captain Guadarrama pulled back on his controls, lifting the 727 off the runway and into the smog-choked air. Despite the long takeoff roll, the climb performance was normal, so Piaget would have called “positive rate,” and Guadarrama would have replied “gear up,” prompting Piaget to raise the landing gear. They could not possibly have known that doing so would seal the fate of everyone on board.</p><p>Like most aircraft of its era, the Boeing 727 was not originally equipped with brake temperature sensors or a brake overheat warning system. The pilots would not have had any way to know that the №1 main landing gear brake was dangerously hot, nor would they have realized that by raising the gear, as they did after every takeoff, they would bring that red-hot brake assembly inside the aircraft.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/750/0*jfTlj_bPUa7lqZtZ.jpg" /><figcaption>An overheated brake on an Airbus A320 after landing. (Joseph Cepril Regalado)</figcaption></figure><p>If an overheated brake is known or suspected, the best practice is to leave the landing gear down, because the airflow will help cool the brake, and if a fire starts, it will be isolated from critical aircraft systems. By contrast, retracting an overheated brake into the landing gear bay will trap the heat in the confined space of the wheel well, where it will be transferred to the surrounding equipment instead of into the open air, dramatically increasing the risk of a fire.</p><p>The components most at risk of damage in such a scenario are, of course, the tires. The brake assembly is attached to the wheel rim, which in turn is attached to the tire, creating a direct heat transfer path. Therefore, should a brake overheat, it could heat the tire until it fails under its normal internal pressure — or the gas inside the tire could heat up, causing it to expand until the tire explodes.</p><p>In order to prevent the latter scenario, aircraft wheels, including those used on the 727, are equipped with fuse plugs that will open to safely deflate the tire in the event that the internal pressure becomes too high. The final report mentions that some aircraft tire explosions have occurred despite the use of fuse plugs, but it also states that none of these previous incidents resulted in damage to critical systems.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*O3fJkj-yoNsAFwh6aEkMaA.png" /></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/552/1*GViCZbKVhPmDycXz6Y5m7A.png" /><figcaption>A couple of references to wheel fuse plugs that I found in Boeing 727 documentation. (Boeing-727.com and Boeing via Avialogs)</figcaption></figure><p>Instead, what happened to flight 940 might have been something else entirely. In fact, according to the analysis by B. F. Goodrich, it probably had to do with the gas that was used to inflate the tires.</p><p>Even at the time, it was common practice to inflate aircraft tires with nitrogen because it’s an inert gas that doesn’t support combustion and doesn’t react as readily with other compounds, and because it doesn’t leak as fast as air. However, this was not strictly required, and it was not unheard of for airlines to inflate their tires with normal air, especially if nitrogen filling equipment was unavailable.</p><p>Although Earth’s atmosphere is 78% nitrogen, most of the rest is oxygen, which is a highly reactive chemical that forms one of the three ingredients required to support combustion (the others being fuel and heat). This is significant in light of the fact that XA-MEM’s tires were inflated with air instead of nitrogen, for reasons not stated in the final report.</p><p>After the accident, B. F. Goodrich engineers examined the fuse plugs from wheel №1 and found particulate matter that appeared to have come from decomposition of the layer of sealant that coats the inner face of the tire. This material, which is not specified in the report, can decompose when exposed to high heat, giving off hydrocarbon gases as a byproduct. Furthermore, if this mixture gets hot enough, then these gases are capable of auto-ignition in the presence of oxygen — remember, fuel plus heat plus oxygen equals fire.</p><p>Therefore, investigators believed that as flight 940 climbed away from Mexico City, the overheated №1 brake started heating the air inside the №1 tire, triggering a decomposition of the sealant layer that released flammable gases into the interior of the tire. As you might recall from <a href="https://admiralcloudberg.medium.com/fire-in-the-fog-the-crash-of-swissair-flight-306-c54893961151">my previous article on Swissair flight 306</a>, the maximum temperature of an overheated wheel assembly may not be achieved until several minutes after the initiating event is over, which means that the temperature of the №1 wheel assembly could have continued increasing for a significant period of time after flight 940 took off. Eventually, the tire’s internal temperature reached the auto-ignition temperature of the hydrocarbon gases, which ignited because the tire was filled with oxygenated air, triggering a powerful explosion as the 727 climbed through 29,400 feet, approximately 14 minutes after takeoff.*</p><blockquote>*Note: Transcripts of communications between flight 940 and ATC, published by international media, show flight 940 reporting at 31,000 feet before the first report of an emergency. The final report says the explosion occurred at 29,400 feet. I was unable to resolve this discrepancy.</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4Ncl6I5bcKswgSFgxSI--Q.png" /><figcaption>Understanding the relative locations of crucial components in the 727’s wheel well area. (Yiming and Boeing-727.com)</figcaption></figure><p>The final report doesn’t appear to completely rule out that the fuse plugs failed to open, allowing the tire to over-pressurize until the weakened rubber failed, but investigators seemingly believed that the power of the explosion was much too great to be explained by this mechanism.</p><p>In fact, the explosion was so large that it was noticed by people on the ground more than 20,000 feet below, who looked up in time to see pieces of the aircraft falling from the sky near the border between Estado de México and Michoacán. These items included but were not limited to a portion of the left landing gear door, the backup electric motor and gearbox for the flaps, pieces of hydraulic lines, and part of the fiberglass cover that protects the fuel supply line to engine №1 where it passes through the left wheel well. This damage indicated that hydraulic lines and the №1 engine fuel feed line were breached at the moment of the explosion, which would have triggered a high pressure fuel leak as jet fuel was propelled through the breach by the still-running fuel pumps. This fuel and hydraulic fluid would have immediately made contact with the scorching surface of the №1 brake assembly, causing a fire.</p><p>Up above, the passengers and crew heard a deafening blast, followed immediately by the roar of an explosive decompression, and in the cockpit, the cabin altitude alarm started blaring, warning that pressurization had been lost. The wheel well itself is unpressurized, so the explosion must have been powerful enough to punch through into the passenger cabin above, leading to a loss of pressure vessel integrity.</p><p>Within seconds of the blast, Captain Guadarrama called Mexico City Area Control Center to request a lower altitude, followed by a request to return to the airport, both of which were granted. The cockpit voice recorder — no transcript of which was released — indicates that the emergency initially presented itself to the crew as a loss of cabin pressure, and that the pilots donned their oxygen masks and initiated a rapid emergency descent, as expected.</p><p>However, due to the immediate ignition of leaking fuel inside the left wheel well, the presence of fire probably became obvious to the passengers within seconds of the explosion. Evidence indicates that the fire spread upward into the passenger cabin, probably early in the sequence of events, due to the breach in the cabin floor. The pandemonium that must have ensued is scarcely worth contemplating, as the 159 passengers and five cabin crew found themselves trapped by roaring flames and choking smoke with nowhere to run.</p><p>Shortly after the emergency call to air traffic control, the cockpit voice recorder captured a flight attendant entering the cockpit to inform Captain Guadarrama that there was a fire on board the aircraft. This would have only increased his urgency to get down, because an uncontrolled fire is probably the most terrifying emergency a pilot can face. Research dating to the late 1990s has shown that from the moment an uncontrolled fire is detected aboard an aircraft, the time remaining until structural failure, loss of control, or forced landing is, on average, 17 minutes. That’s not a lot of time for an aircraft at its cruising altitude to get to an airport. And if you find yourself fighting one of the 50% of uncontrolled fires that necessarily leave less than 17 minutes available, then god help you.</p><p>The fire on board Mexicana flight 940 was beyond even that worst case scenario. Within a very short time of its ignition, it began to spread aft along the underside of the fuselage, drawn backward by the suction force of the airflow streaking past the opening created by the missing landing gear door. The heat became so intense that the aircraft structure itself started to melt, sending white-hot rivulets of molten aluminum streaming in its wake.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*HA4FHWp0DR6bP-5UYZMQFA.png" /><figcaption>Artist’s impression of the fire aboard Mexicana flight 940, by my good friend Chloe Howie of Disaster Breakdown over on YouTube. Watch her full video on this crash here: <a href="https://www.youtube.com/watch?v=8TSfzDtxfzM">https://www.youtube.com/watch?v=8TSfzDtxfzM</a></figcaption></figure><p>The final report doesn’t say whether the breach in the fuel supply line for the №1 engine caused that engine to shut down. However, it’s doubtful that the pilots would have had time to complete the engine shutdown procedure, which would have involved cutting off fuel flow to the engine. In fact, the final report does mention that the fuel leak continued under high pressure due to operation of the auxiliary pumps in the fuel tanks, without providing any context (for example, the significance of the auxiliary pumps as opposed to other pumps in this scenario, whether this was expected behavior of the fuel system with a breach in this location, etc.). Therefore, the supply of pressurized fuel was probably a major cause of the fire’s rapid and continuous intensification. However, the final report also points out that while a fire fed by jet fuel maxes out at around 2,000˚F (1,100˚C) under normal conditions, temperatures as high as 3,000˚F (1,650˚C) can be reached when the fire is exposed to high-speed airflow on the exterior of a moving aircraft.</p><p>The fact that the fire was spreading along the outside of the aircraft by this point was established by witness reports of an obvious fire on the aircraft, with pieces continuously peeling off in its wake, falling like bright streamers to the earth below. As for what was happening in the passenger cabin, only the dead can say.</p><p>Around this time, the final report states that one of the pilots requested a diversion to Morelia, which was closer than Mexico City, although the air traffic control transcripts published by media at the time don’t reflect this request. The cockpit voice recorder also captured the crew discussing unspecified control difficulties, presumably because the fire was beginning to affect the cables connecting the pilots’ control columns to the flight control surfaces in the wings and tail.</p><p>No transcript of the CVR was provided, nor does the final report contain any detailed timeline of events on board the aircraft, so it’s difficult to know what the pilots did to ameliorate the situation during those critical minutes — not that any of it would have made much difference. The entire lower aft section of the airplane was completely consumed in flames, rapidly eating away at its structural integrity, and the aft-mid passenger cabin was probably engulfed as well. The final report doesn’t address the topic, but it’s safe to assume that some, perhaps even many, of the passengers perished while the plane was still in the air.</p><p>In the end, XA-MEM withstood the fire for only four minutes — one of the shortest burn times of any in-flight fire accident in the history of commercial aviation. Such was the awesome power of the blaze that the plane practically turned to ash underneath the pilots’ feet.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Uu0BzMaKVi9xhlajxfFm4Q.png" /><figcaption>Chloe Howie’s continued impression of the forward section of the airplane falling after separation of the empennage.</figcaption></figure><p>At approximately time 09:08, witnesses caught sight of the plane descending over the Sierra Madre mountains east of the municipality of Maravatío. The entire rear half of the aircraft was shrouded in flames, billowing and streaming, tearing at the disintegrating structure, until it finally gave way. With a mighty rending of metal, the burning airplane broke in half just behind the wings, sending the tail section plummeting to earth, carrying with it all three engines, all the pitch control surfaces, and about 20 passengers and crew seated in the rearmost rows. The remainder of the airplane hurtled onward, pitching uncontrollably forward as it fell, turning inverted, until its meteoric plunge was abruptly halted by the immovable bulk of the mountainside below.</p><p>In the Mexico City Area Control Center, flight 940 disappeared from radar. Controllers tried in vain to contact it, but their efforts were met with an eerie radio silence.</p><p>◊◊◊</p><iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FyysEb7Qf97M%3Ffeature%3Doembed&amp;display_name=YouTube&amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DyysEb7Qf97M&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FyysEb7Qf97M%2Fhqdefault.jpg&amp;type=text%2Fhtml&amp;schema=youtube" width="854" height="480" frameborder="0" scrolling="no"><a href="https://medium.com/media/49a63a5f27837c2158418b9c7f1e6ec1/href">https://medium.com/media/49a63a5f27837c2158418b9c7f1e6ec1/href</a></iframe><p>Minutes after the crash, aerial search teams spotted the wreckage scattered across the upper slopes of a 10,000-foot peak called El Carbón, where smoke rose from the trees and chaparral on both sides of a steep, untracked ravine above the village of San Miguel el Alto. With nowhere to land a helicopter, rescuers were forced to climb to the site on foot, where they found the main fuselage and wings burning on the mountainside, with the nearly intact tail section lying amid the trees on the opposite flank of the valley, several hundred meters distant. Residents of San Miguel el Alto who saw the plane come down shared their belief that no one could have survived, and indeed, upon their arrival the rescuers found only desolation. All 167 people on board were dead — the worst air disaster ever to occur in Mexico.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*HBUyd8Xrq6ts_MhV.jpg" /><figcaption>The tail section of flight 940 came to rest more or less intact on a forested mountainside. 20 bodies were reportedly found inside. (Bureau of Aircraft Accidents Archives)</figcaption></figure><p>The investigation into the crash was led by the Aircraft Accident Investigation and Reporting Commission of the Mexican Directorate General of Civil Aeronautics, with participation by representatives of the United States National Transportation Safety Board, Boeing, and the Federal Aviation Administration. This investigation team gathered wreckage from disparate sites all along the flight path, starting from a point 32 km east of the impact site, where witnesses confirmed that an explosion had occurred aboard the plane.</p><p>The cause of the explosion was not immediately apparent, and some parties jumped the gun in their attempts to explain it. Two Middle Eastern terrorist groups lodged opportunistic claims of responsibility for the crash, describing it as revenge for US actions in Libya, but there was no evidence of their involvement. Separately, however, a group of Mexicana pilots, as well as representatives of the International Federation of Air Line Pilots Associations, told the media days after the accident that they believed the plane was brought down by a bomb — and not as an act of terrorism, but rather in an attempt to collect on a passenger’s life insurance policy.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pBVyDiA8AuuDz1CDKGDXAw.png" /><figcaption>The approximate location of the wreckage of flight 940 near San Miguel el Alto. (Google)</figcaption></figure><p>However, examination of the components found at the site of the explosion and along the flight path revealed that they came from the left wheel well, not from any cargo compartment, and chemical analysis of the parts found no traces of explosive residue. As a result, while an explosion clearly took place, sabotage was quickly ruled out.</p><p>The contents of the final report show that the Commission did gather and document the wreckage, weather information, flight crew information, and other standard elements of the initial fact-finding phase of any air accident investigation. The cockpit voice recorder and flight data recorder were also recovered and read out, although virtually no information from the recorders was included in the final report. Components believed to be related to the source of the explosion, including the recovered brake assemblies, were sent to the manufacturers for testing, as is standard practice, and in return reports were received describing the condition of the elements and the manufacturers’ opinions as to the causes of the damage to those elements. However, the final report contains little to suggest that any further investigative actions were performed beyond this point.</p><p>Normally, once the fact-finding phase has concluded, an extensive period of testing and analysis follows. Investigators conduct experiments to evaluate causal mechanisms and potential contributing factors, and consider the actions of various actors, including pilots, mechanics, and others, in light of the accident circumstances, applicable procedures, and prevailing culture. These efforts add clarity to what happened and start to peel away the veil around the systemic factors that created the accident risk in the first place.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*ImngeUNvklqvhaVS" /><figcaption>The front page of El Universal the day after the accident.</figcaption></figure><p>In this case, though, it doesn’t appear that any of that was done. The “tests and research” section of the final report contains only those tests performed by B. F. Goodrich and Boeing, with no evidence of independent experiments. The section concludes with a declaration that the “final analysis of all the information” established an accident scenario that was essentially identical to that put forward by B. F. Goodrich, with some additional elements added by the Commission, possibly related to a bench test on some 727 tires, which is briefly alluded to in the conclusions section.</p><p>The analysis section, which follows “tests and research,” was even weaker. This section reads like a conclusion section, simply listing facts and determinations that had already been made, establishing an extremely rough and incomplete causal chain, but without any actual analysis. The section also omits any discussion of the possible causes of the explosion and contains no discussion of any brake malfunction, despite the evidence laid out in the preceding sections. The brake malfunction is not mentioned again until the probable cause section, and no attempt to establish the reasons for the brake malfunction appears to have been made. Were it not for the inclusion of a probable cause statement, I might have mistaken this for an interim report instead of a final report.</p><p>On the one hand, this final report bears the hallmarks of a probe led by a team that lacked expertise in the art of air accident investigation and relied almost entirely on expert reports submitted by the aircraft manufacturer and its suppliers. But on the other hand, one paragraph in the report contains an interesting admission that suggests there might be more to the story. This paragraph reads, in English, translated from the original Spanish:</p><p><em>“The Attorney General’s Office intervened in the investigation of this accident by virtue of law and provided extensive and valuable assistance to the Investigative Commission of the Directorate General of Civil Aeronautics. The results of the Attorney General Office’s investigations appear in the analysis and conclusions of this report.”</em></p><p>This could mean one of two things: first, that the Attorney General’s Office provided some unspecified assistance that resulted in some information that was added to the analysis and conclusions section; or second, that the <em>entirety</em> of the analysis and conclusions belong to the Attorney General’s Office. Now, why would the Attorney General’s Office intervene in an aircraft accident investigation? In my opinion, the most likely explanation is that they became involved in order to determine whether the explosion was accidental or intentional. It is therefore plausible, but not certain, that once the explosion was found to be accidental, the Attorney General’s Office simply had the investigation wrapped up without much if any further inquiry. That would certainly explain why the analysis section is so perfunctory, but it’s far from the only explanation.</p><p>As I mentioned earlier in the article, and in previous articles, hurrying to end an investigation by some arbitrary deadline limits the scope of the safety lessons that may be learned, doing a disservice to the airline industry and the traveling public. Unfortunately, these types of incomplete investigations were not uncommon in decades past, and they still sometimes happen today in various parts of the world. While I appreciate the need to reach conclusions quickly so that urgent issues can be addressed, that’s what interim reports and mid-inquiry safety recommendations are for.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/567/0*voPNXv9v5MvMH4jN" /><figcaption>Rescuers sort through the wreckage of the main portion of the aircraft. (El Universal)</figcaption></figure><p>◊◊◊</p><p>In the end, the investigators concluded that a dragging brake overheated the №1 wheel and the air inside it, triggering an explosion that destroyed fuel and hydraulic lines, causing an intense fire that compromised the aircraft’s structural integrity, leading to an in-flight break-up of the airplane. The events portrayed in this article are essentially those endorsed by the Commission’s final report, with only minor points of addition. Unfortunately, the systemic causes of the accident are unknown.</p><p>Nevertheless, some good did come of the findings. In response to the conclusion that air in the №1 tire likely permitted auto-ignition of flammable gases, causing a much more powerful explosion, on June 1st, 1987 the Federal Aviation Administration issued an Airworthiness Directive applicable to all US transport aircraft requiring that tires be filled with nitrogen only. The AD also established rules and limitations pertaining to the use of air at airports where nitrogen filling equipment is unavailable. These measures have greatly reduced the risk posed by aircraft tire explosions.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TXjTarYNOxsW-JeUfTILmQ.png" /><figcaption>The text of the FAA’s 1987 Airworthiness Directive. (FAA)</figcaption></figure><p>However, one safety risk not addressed by this investigation was the lack of brake overheat warnings and wheel well fire warnings on most transport category aircraft. The original Boeing 727 was not equipped with brake temperature sensors at all, and as far as I can tell it’s still not a requirement that transport aircraft possess such sensors, as long as procedures are in place to ensure appropriate brake temperatures before, during, and after operation. Nevertheless, many aircraft today do have such sensors, even though they’re not required.</p><p>The Transportation Safety Board of Canada cited the lack of brake temperature sensors on the Fairchild/Swearingen Metro III aircraft in its investigation into the 1998 crash of Propair flight 420 in Montreal, Canada, as a result of a dragging brake that overheated and caused a wheel well fire. The agency pointed out that as of that date, brake temperature sensors were not required for certification, but would have helped the crew of flight 420 avoid retracting the overheated brake into the wheel well.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KbNBqvNn-h_Uscqt8Xo3Jw.png" /><figcaption>An excerpt from the TSB of Canada’s report on the 1998 crash of Propair flight 420.</figcaption></figure><p>To my knowledge, large transport category aircraft today typically also have sensors that trigger a warning in the event of excess heat or fire in the wheel wells, as a result of several accidents including Mexicana flight 940, as well as Nationair/Nigeria Airways flight 2120, <a href="https://admiralcloudberg.medium.com/inferno-on-the-hajj-the-crash-of-nigeria-airways-flight-2120-1f45831b6aef">which you can read about here.</a> For instance, a Boeing 727 manual dated to after those accidents includes procedures for responding to a wheel well fire warning — something that XA-MEM apparently did not have. The procedure in the event of such a warning is to maintain an airspeed below the maximum landing gear extension speed, extend the gear, leave the gear doors open, then monitor the wheel well fire warning light to determine whether it extinguishes. If it does, the procedure is to wait 20 minutes to ensure sufficient time for the brakes to cool. If it does not, then the procedure is to “land at the nearest suitable airport.”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/828/1*MTZnu1H8a26w3PFKOrBHjA.png" /><figcaption>The wheel well fire procedure from a later model Boeing 727. (Boeing via Avialogs)</figcaption></figure><p>If the crew of Mexicana flight 940 had access to a wheel well fire warning triggered by excessive heat, as I believe such sensors typically are, then they might have been able to prevent the explosion and fire that ultimately destroyed their airplane.</p><p>FAA regulation 14 CFR 25.863 also requires that manufacturers minimize the possibility of ignition in any area where flammable fluids or vapors are present, including jet fuel or hydraulic fluid. A current draft advisory circular describing the most recent acceptable methods of compliance with this provision, which has not yet been officially published but is receiving industry comment, states that the wheel well is such an area and lists several ways to mitigate the danger with regard to the requirements of 14 CFR 25.863. These methods include but are not limited to <em>“installation of fluid systems, especially fuel, so that leakage does not enter the wheel well;” “volumetric fuses on brake lines or other brake design features to limit amount of hydraulic fluid that can feed a brake fire;” “means, such as shrouds, to minimize the probability that leaking flammable liquids would contact a hot brake surface;” “installation of a wheel well overheat/fire detector combined with procedures to extend the gear or otherwise cool/extinguish the fire if an overheat/fire is detected;”</em> and <em>“installation of brake temperature indication combined with procedures to not retract the gear (or extend the gear if retracted) until the brake temperatures are within limits.”</em> My non-professional impression would be that XA-MEM probably did not meet the criteria proposed in this draft advisory circular, although the 727’s wheel well did incorporate some protective features, such as the fiberglass shroud around the №1 engine fuel line, which nevertheless failed to withstand the force of the tire explosion.</p><p>In any case, what I want to convey is that aircraft today are much better protected against wheel well fires than XA-MEM was, and the probability of a similar accident is, in my opinion, extremely low. Nevertheless, in the 15 years immediately after the crash of flight 940, several similar accidents did occur, which is part of why I’ve spent so much time talking about where the final report fell short. Phoning it in because you think a similar accident will never happen again is a great way to end up eating a hat.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/640/0*hRpjt-w7ZIsOCE6T" /><figcaption>A closer view of the tail section. (Bureau of Aircraft Accidents Archives)</figcaption></figure><p>◊◊◊</p><p>As a concluding note, the lack of information about some crucial parts of the story meant that this article almost didn’t get written, but I decided to go ahead and write it anyway because I still had something to say. That doesn’t mean I don’t wish there was more to be said about Mexico’s deadliest air disaster, a monumental tragedy that should have been more impactful than it was. The 167 souls lost in the inferno over Michoacán deserved a proper accounting of their fate and a reckoning with its systemic causes — one that their families never received. What they endured was a hell beyond description, four minutes of unimaginable terror, followed by a swift and violent end. They were people with hopes, dreams, and plans; they had friends, kids, parents, siblings, and spouses. At least twenty of them were children. How is it even possible, as human beings, not to pursue the causes of that enormous anguish until every thread has been pulled? Closure may be a myth, but knowledge isn’t, and without it the pain is so much greater.</p><p>_______________________________________________________________</p><p><em>Don’t forget to listen to Controlled Pod Into Terrain, my podcast (with slides!), where I discuss aerospace disasters with my cohosts Ariadne and J! </em><a href="https://www.youtube.com/@ControlledPodIntoTerrain"><em>Check out our channel here</em></a><em>. Alternatively, download audio-only versions via </em><a href="https://rss.com/podcasts/cpit/"><em>RSS.com</em></a><em>, or look us up on Spotify!</em></p><p><em>You can also see my work on Petter Hornfeldt’s YouTube channel “Mentour Pilot,” where I’m employed as a script writer and researcher.</em></p><p>_______________________________________________________________</p><p><a href="https://www.reddit.com/r/AdmiralCloudberg/comments/1odjjdz/four_minutes_over_mexico_the_crash_of_mexicana_de/">Join the discussion of this article on Reddit</a></p><p><a href="https://www.patreon.com/Admiral_Cloudberg">Support me on Patreon</a> (Note: I do not earn money from views on Medium!)</p><p><a href="https://bsky.app/profile/kyracloudy.bsky.social">Follow me on Bluesky</a></p><p>Visit <a href="https://www.reddit.com/r/AdmiralCloudberg/">r/admiralcloudberg</a> to read and discuss over 260 similar articles</p><p><a href="https://docs.google.com/document/d/1FPHbSSeBBDsbPOOCllbNOaGMMWufrp7Eg_GgT0i7Nzw/edit?usp=sharing"><strong>Bibliography</strong></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=d71f213a47c6" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Crucible of the Cascade: The crash of Gazpromavia flight 9608]]></title>
            <link>https://admiralcloudberg.medium.com/crucible-of-the-cascade-the-crash-of-gazpromavia-flight-9608-50e225baece3?source=rss-e119a26506e3------2</link>
            <guid isPermaLink="false">https://medium.com/p/50e225baece3</guid>
            <category><![CDATA[flying]]></category>
            <category><![CDATA[aviation]]></category>
            <category><![CDATA[technology]]></category>
            <category><![CDATA[russia]]></category>
            <dc:creator><![CDATA[Admiral Cloudberg]]></dc:creator>
            <pubDate>Sun, 14 Sep 2025 02:20:46 GMT</pubDate>
            <atom:updated>2025-10-24T23:27:28.958Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WCNQVuTPEZRxHH_KGcGlMg.png" /><figcaption>An aerial view of the crash site of Gazpromavia Flight 9608. (MAK)</figcaption></figure><p>On the 12th of July 2024, a Sukhoi Superjet 100 operating for Russian state oil company Gazprom lost control and plunged into a forest just five minutes after takeoff on what should have been a brief repositioning flight. The weather was perfect, the crew were well rested, and the airplane had just been released from a thorough round of inspections — so what went wrong? The answer, it turns out, is both technically complex and viscerally horrifying.</p><p>One year after the accident, the release of the final report has revealed a scarcely believable sequence of events that began with a colossal maintenance mix-up enabled by suboptimal aircraft design. Unaware that their airplane had been rendered grossly unairworthy, the pilots attempted to reposition it for its next scheduled flight, only to find themselves barraged with a series of confusing indications, followed by a terrifying and ultimately unsuccessful fight for control as the fly-by-wire SSJ-100 seemingly tried to fly itself into the ground. Minute variations in parameters and apparently minor crew decisions triggered a complex automation “cascade,” culminating in a catastrophic coupling of two different flight envelope protections that should never activate simultaneously.</p><p>The pilots spent their final moments hauling back on their side sticks in a desperate effort to climb, unable to overcome a computer governed by the inexorable logic of its programming. From the drawing boards of the United Aircraft Company to the final actions of the doomed crew, this is the story of how it happened.</p><p>◊◊◊</p><p><em>Hello readers! At the end of July, the final report on this accident report was released, in Russian only. (Annex 13 to the Chicago Convention on Civil Aviation, to which Russia is a signatory, requires that accident investigation reports be published in English to facilitate global distribution and awareness). Since I have a master’s degree in Slavic Studies with a focus on Russian language, I took it upon myself to translate the entire 263-page report, which occupied me throughout the month of August. As a courtesy, I’m releasing my translation to the public alongside this article, and </em><a href="https://drive.google.com/file/d/1HsWVb2nSlt2saL06K4VXDqDjzUMQC17t/view?usp=sharing"><em>you can read it here.</em></a></p><p>◊◊◊</p><h3>Part 1: Just a Short Flight</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*tIDoKZKYA131juRIl_TyTQ.png" /><figcaption>If you want to learn more about what it was like to fly on Gazpromavia in 2015 as a foreigner, I recommend this at times highly amusing article by Bernie Leighton of Airline Reporter: <a href="https://www.airlinereporter.com/2015/09/gazpromavia-they-have-yak-42s-what-more-do-you-need/">https://www.airlinereporter.com/2015/09/gazpromavia-they-have-yak-42s-what-more-do-you-need/</a></figcaption></figure><p>If, for some reason, you were to find yourself searching for flights to Russia’s far northern gas-producing towns of Nadym and Novy Urengoy, you may discover the option to purchase tickets on a highly unusual airline called Gazpromavia.</p><p>As the largest company in Russia and the world’s top producer of natural gas, the state-owned Gazprom wields immense power over Russia’s economy and society, with hundreds of subsidiaries across many industries, including a bank, a media holding company with 38 television channels, and even a private mercenary army that actively participates in the invasion of Ukraine. As a vertically integrated company, Gazprom also owns every element of its gas production process, from exploration to extraction to refining to distribution. This includes air transportation of personnel and equipment, often to remote destinations in the Arctic and Siberia, for which its dedicated subsidiary Gazpromavia operates a fleet of more than 30 fixed wing aircraft and over 100 helicopters. Most of these are directly engaged in gas extraction support roles, as well as charter operations, but a few aircraft are used for scheduled passenger flights, just like any other airline. In fact, you can go online right now and purchase tickets on Gazpromavia flights between Moscow, Ufa, Tyumen, Nadym, and Novy Urengoy, not that I recommend giving Gazprom your hard-earned money. Other destinations might also be available, but a full accounting of the company’s scheduled network was difficult to find.</p><p>Gazpromavia’s base of operations is at Vnukovo International Airport, located on the southwestern outskirts of Moscow. In 2024, the airline’s Vnukovo-based fleet consisted of 9 Sukhoi Superjet 100 (SSJ-100) short-to-medium-range jets configured with 90 passenger seats each.</p><p>That same year, Gazpromavia began contracting routine maintenance and heavy inspections to the Civil Aircraft Maintenance and Overhaul Center, or MOC, at the P. A. Voronin Lukhovitsy Aircraft Plant in the town of Lukhovitsy, located 120 kilometers southeast of Moscow.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*nDKLSkHo3FX2GAoE" /><figcaption>The Lukhovitsy Aircraft Plant. In recent months, the plant has allegedly been targeted by Ukrainian drones. (Astrapress)</figcaption></figure><p>The Lukhovitsy Aircraft Plant and the attached Tretyakovo Airport have been owned and operated for decades by Russian aircraft manufacturer Mikoyan and Guryevich, or RAC MiG, which built and maintained notable warplanes at Lukhovitsy, including the MiG-29. Like all other Russian aircraft manufacturers, MiG is now part of the United Aircraft Company, or UAC, as are the factory and the airport.</p><p>MiG has not designed and produced a new aircraft type since the fall of the Soviet Union, instead subsisting mainly on continuing maintenance revenue from the existing fleet of MiG warplanes. However, this is a finite and declining revenue source. In 2015, for instance, a fighter expert told the Moscow Times that MiG’s maintenance and upgrade business “will disappear as export customers retire, store, scrap and replace their MiG-29s.” Although at the time UAC disputed the notion that MiG was in trouble, in 2022 the company was merged with Sukhoi Aircraft, another UAC subsidiary and the manufacturer of the SSJ-100 regional airliner. As part of this process, in 2021 UAC opened the Civil Aircraft Maintenance and Overhaul Center at the Lukhovitsy Aircraft Plant in order to maintain SSJ-100 aircraft using the plant’s existing MiG technical staff.</p><p>Three Gazpromavia SSJ-100s underwent maintenance and inspections at the Lukhovitsy MOC in 2024, including an aircraft with registration number RA-89049.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*gjTmtCHEvBIsrqZb.jpg" /><figcaption>RA-89049, the aircraft involved in the accident. (Aleksey Simanovich)</figcaption></figure><p>On the 12th of July 2024, that aircraft was released from maintenance, and a Gazpromavia flight crew was sent to Tretyakovo Airport in order pick it up and reposition it to the airline’s operating base at Vnukovo. After completing all pre-flight checks, the crew established contact with the Tretyakovo Air Traffic Manager — the equivalent of an air traffic controller at the privately owned, non-public airport — and received permission to taxi at 14:48 local time. Takeoff clearance was granted five minutes later.</p><p>The flight to Vnukovo Airport was not expected to be a long one. The two airports are only 136 km apart, and the crew of RA-89049 didn’t expect to climb any higher than 10,000 feet before beginning their descent. The airplane was light and responsive with no passengers or baggage on board, and the weather was perfect, with unlimited visibility and few clouds throughout the wider Moscow region.</p><p>Following takeoff from runway 10, the flight executed a left turn to a heading of 004 degrees, after which the crew used their second radio to contact Domodedovo Radar, the air traffic control division responsible for mid-level airspace around Moscow’s Domodedovo International Airport. After coordinating with the Tretyakovo tower, the controller cleared them for a further left turn to heading 260, the direction of Vnukovo Airport, with an unrestricted climb to 10,000 feet. Using the flight’s callsign, the Domodedovo radar controller asked, “Gazprom 9608, and tell me if you’re ready to follow on to Vnukovo? And what altitude will you need?”<br> “Yes, we’re ready for Vnukovo immediately, but we don’t have any need for higher than ten [thousand], 9608,” the captain replied.</p><p>Some 30 seconds later, the Domodedovo Radar controller glanced back at his display and noticed that flight 9608 had not begun climbing to 10,000 feet — in fact, it was at 5,000 feet and descending. Assuming there had been some misunderstanding, he addressed the flight: “Gazprom 9608, confirm climb to ten thousand feet?” But there was no reply.</p><p>At Tretyakovo Airport, the air traffic manager heard flight 9608 reporting “unreliable airspeed,” but the Domodedovo controller did not hear the transmission and continued to inquire with mounting alarm. But he would not hear from the flight again. Instead, he watched helplessly as the aircraft’s descent steepened and its speed increased, its altitude ticking down toward zero, until at time 14:59 and 16 seconds, it vanished from radar.</p><iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FDUEM-TNFEtY%3Ffeature%3Doembed&amp;display_name=YouTube&amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DDUEM-TNFEtY&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FDUEM-TNFEtY%2Fhqdefault.jpg&amp;type=text%2Fhtml&amp;schema=youtube" width="640" height="480" frameborder="0" scrolling="no"><a href="https://medium.com/media/cfb70631843237f378eec0c583b04390/href">https://medium.com/media/cfb70631843237f378eec0c583b04390/href</a></iframe><p>At the Tretyakovo tower, the air traffic manager observed a column of black smoke bursting abruptly from a distant forest, testifying to the violent end of RA-89049. He immediately activated the crash alarm, and at Domodedovo Airport, the control center supervisor did the same.</p><p>Reports of an airliner down spread quickly to multiple emergency agencies, which collectively sent 381 personnel and 120 vehicles to the site of the crash to contain the fire, search for survivors, and provide site access. But when they got there, they found little more than a smoldering hole in the broadleaf forest, where the burning remnants of what had once been an SSJ-100 lay strewn across the forest floor for a distance of nearly 400 meters. Within this colossal scar, they discovered the bodies of two pilots and a flight attendant, who had been the only people on board. There were no survivors.</p><p>◊◊◊</p><p>In accordance with Russian law, responsibility for the investigation lay with the Interstate Aviation Committee, or MAK, an independent multinational aviation organization headquartered in Moscow and active in several former Soviet republics. The MAK is a recurring character in my articles, but if you’re not familiar with them, then it suffices to say that the MAK is one of the last civil organizations in Russia to have largely escaped cooption by Russian state interests, at least for now. You can read more about my thoughts on the agency and its history <a href="https://docs.google.com/document/d/1hVnzJ6HqgOxKUYZX2m5fUXPHipSf_j4U/edit?usp=sharing&amp;ouid=100007588750159924865&amp;rtpof=true&amp;sd=true">here</a>, <a href="https://admiralcloudberg.medium.com/someone-elses-problem-the-crash-of-tatarstan-airlines-flight-363-ff5a6177e180">here</a>, and <a href="https://admiralcloudberg.medium.com/trial-by-fire-the-crash-of-aeroflot-flight-1492-ee61cebcf6ec">here</a>.</p><p>The MAK isn’t known for publishing reports quickly — the final report on the crash of Aeroflot flight 1492 infamously took nearly six years to come out — but it seems that the crash of Gazpromavia flight 9608 bucked that trend. Despite conducting extensive experiments involving complex mathematical models, the MAK published its final report after just one year. The text of the report reveals much about what happened that day, and reading between the lines reveals a little bit more — and not all of it is pretty.</p><p>◊◊◊</p><h3><strong>Part 2: The Gazprom Bucket Brigade</strong></h3><p>The Sukhoi Superjet 100 is the most successful Russian airliner designed and built since 1991, but it does not have stiff competition. Around 235 have been built (Wikipedia says “Citation needed”), and airlines in several countries previously flew them, but most dropped the type quickly due to lower-than-advertised reliability and a shortage of spare parts. Today, several dozen are in service with the Russian government and various Russian airlines, but as of 2025 the only remaining operator outside of Russia is the Kazakh border patrol.</p><p>The SSJ-100 started life as an international project born of a partnership between the United Aircraft Company and several western aerospace companies. The engines are a collaboration between France’s Safran and Russia’s NPO Saturn; the avionics are from France’s Thales Aerospace; the flight control systems are made by Germany’s Liebherr; the auxiliary power unit is manufactured by America’s Honeywell; and the electrical system is from Hamilton Sundstrand. Most of the fuselage and wings are manufactured in Russia, but almost everything else comes from abroad, much of it consisting of off-the-shelf components.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/960/0*v7oLh5OOdEbe92Cx" /><figcaption>SSJ-100 suppliers. (Sukhoi Aircraft Company)</figcaption></figure><p>Where once these Western suppliers were marketed as a benefit, they are now a liability. Sanctions imposed on Russia following the 2022 invasion of Ukraine have cut off the supply of spare parts and technical support from suppliers in the US and Europe, forcing Russian airlines to seek alternative supply chains, including but not limited to the black market. Some have also grounded aircraft in order to strip them for parts.</p><p>Even before the invasion, UAC had been seeking to “Russify” the SSJ-100 by replacing foreign-made components with Russian equivalents, a process known as import substitution. As part of this process, the SSJ-100 type certificate was handed to Yakovlev — formerly known as Irkut — which renamed the project to the SJ-100 or “Superjet New.” Despite lofty promises, as of this writing no import-substituted SJ-100 has been delivered to any airline and it is unclear when or even whether this will occur. According to various sources, the CEO of Yakovlev was removed from his post in late 2024 due to the lack of progress, but it could hardly be considered his fault: at present, Russia is struggling to find the technical and manufacturing expertise needed to replace Western systems without large efficiency losses that could make the planes uneconomical to fly.</p><p>In the meantime, airlines wait and make do.</p><p>◊◊◊</p><p>On 20 March 2024, Gazpromavia SSJ-100 RA-89029 arrived at the Maintenance and Overhaul Center at the Lukhovitsy Aircraft Plant in order to undergo a series of standardized heavy inspections and preventative maintenance. These inspections could be described as a C-check, although this was not technically the case. Most airliners have a standardized inspection regime consisting of A, B, C, and D checks, each of which involves increasing thoroughness and complexity and an increased time interval between checks. Typically, a C-check happens about once every two years, but this will depend somewhat on the aircraft type and operating style. On the other hand, UAC doesn’t provide a strictly consolidated inspection regime; instead, it defines the maximum acceptable inspection interval for each system and allows airlines to organize the individual inspection items into packages at their convenience, so long as no maximum intervals are exceeded. Therefore, RA-89029 was not in fact undergoing a C-check, but rather a “1C+5C-check,” as defined by Gazpromavia, consisting of elements to be inspected and serviced every two years, combined with elements to be inspected and serviced every ten years. On most aircraft types this would be considered a combined C and D-check, but SSJ-100 operators are free to call it whatever they want; for instance, in 2023, the Lukhovitsy MOC performed routine inspections and servicing on a Yamal Airlines SSJ-100 according to what that airline termed a “2920DY+1460DY+730DY+7500FH+ADD” check (presumably consisting of combined 7,500 flight hour inspection items, 2-year inspection items, 4-year inspection items, 8-year inspection items, and whatever ADD means).</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*S8rA4vjplwvwh55b.jpg" /><figcaption>RA-89029, the first Gazpromavia aircraft to arrive at Lukhovitsy. (Marian Chovancak)</figcaption></figure><p>This misbegotten story begins with the 5C-check on RA-89029. The exact scope of this check is not described in the final report, but what’s important is that Gazpromavia had apparently requested that the Lukhovitsy MOC replace the aircraft’s two primary angle of attack sensors while the airplane was down for inspection.</p><p>The angle of attack is the angle between the lifting surfaces and the oncoming airflow. Generally, this can be expressed as the pitch angle minus the flight path angle. For instance, an aircraft that is pitched 10 degrees up but climbing on a 7 degree slope has an angle of attack of 3 degrees, at least in theory (assume spherical cow, etc, etc).</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*uvHGjKw71lsATdvj.jpeg" /><figcaption>A helpful illustration of angle of attack for my non-aviation readers. (Aviation Performance Solutions).</figcaption></figure><p>The angle of attack, or AOA, is crucial for flight because it’s a key component of the lift equation, and thus a higher angle of attack results in more lift, up to a point. Above that point, the air stops flowing smoothly over the upper wing surface, lift decreases dramatically, and a stall occurs, causing the airplane to fall from the sky. Therefore, the first angle of attack sensors were developed primarily with the intention to warn the flight crew if that point is approaching. On some conventional airliners, especially very old, less computerized ones, this remains the main purpose of the AOA sensor — to feed angle of attack information to the stall warning system. Although most aircraft also have AOA indicators for the flight crew, these are not usually considered a primary or essential instrument.</p><p>On the other hand, heavily computerized aircraft — and fly-by-wire aircraft in particular — rely much more heavily on angle of attack data. The SSJ-100 is a fly-by-wire aircraft, meaning that the pilots’ side sticks are not directly connected to the flight control surfaces. Instead, moving the side stick sends a pitch or roll command to an array of flight computers that interpret how the control surfaces should move in order to achieve the aircraft state commanded by the crew, taking into account airspeed, configuration, and a whole host of other parameters, including flight envelope limitations, stability characteristics, and so on. How exactly this process works will be covered in more detail in Part 3. For now, it suffices to understand that the angle of attack data is used for two main purposes that are relevant to this story: first, to apply a correction to the measured ambient (or static) pressure, used in calculating altitude and airspeed, in order to account for differences in airflow across the static pressure sensors at different angles of attack; and second, to inform the fly-by-wire system’s flight envelope protections, so that they can act to prevent the angle of attack from ever reaching the stall threshold.</p><p>In order to supply vast quantities of verified and trustworthy data to the fly-by-wire system, the SSJ-100 has three redundant air data systems, or ADSs, each of which collects raw information from sensors, including static pressure sensors, dynamic pressure sensors (pitot tubes), angle of attack sensors, temperature sensors, and so on; processes the data into a usable format; checks it for validity; and distributes it to aircraft systems, including the fly-by-wire system. The captain’s instruments by default use air data from ADS 1; the first officer’s from ADS 2; and the standby or backup instruments from ADS 3, while the fly-by-wire system uses consolidated parameters derived from all three ADSs in order to ensure the highest level of parametrical integrity.</p><p>This redundancy is possible because each ADS has its own set of sensors. In the case of AOA, ADS 1 receives angle of attack data from the №1 AOA sensor on the left side of the aircraft, while ADS 2 receives data from the №2 AOA sensor on the right side. These two AOA sensors are considered the “primary” sensors because their data is directly incorporated into the instrument indications normally used by the flight crew. However, ADS 3 — the standby system — has not one but two AOA sensors, one on each side of the airplane, bringing the total to four.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*z8wV04YUG3BWGR2O43Eiaw.png" /><figcaption>The locations of all air data sensors on the exterior of the fuselage. (MAK)</figcaption></figure><p>Each individual AOA sensor consists of a vane attached to a rotating shaft with a range of motion of approximately ±40 degrees. As the airplane flies through the air, the vane rotates to align with the local airflow. The position of the vane is measured by a resolver and transmitted to the corresponding air data computer (ADC), which applies a correction algorithm to convert the vane position into the actual aircraft AOA.</p><p>The AOA sensor shaft rotates inside a set of bearings, which are contained within a housing. The housing, the shaft, the bearings, and the vane collectively make up the single unit that is the AOA sensor. If a problem with an AOA indication is identified, technicians can simply remove the faulty unit and replace it with a correctly functioning unit.</p><p>Each AOA sensor fits into a prefabricated opening in the associated fuselage skin panel. The nature of this attachment is spatially complex, but it’s also beyond critical to this story, so bear with me here.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*j2Lqpn03OkEocX_KR1StnQ.png" /><figcaption>A basic diagram of an AOA sensor. (MAK)</figcaption></figure><p>The element that fixes the AOA sensor in place within this opening is a part called the “overlay” (Ru: <em>накладка</em>). The overlay is a circular piece of metal, slightly wider than the fuselage opening, with a small circular cutout in the center to accommodate the protruding vane. Around the inner circumference of the overlay, five holes are drilled to accommodate five screws that affix the overlay to the housing, while allowing the shaft and vane to rotate freely. At the same time, the outer circumference of the overlay features 15 holes, spaced 24 degrees apart, that correspond to 15 equally spaced holes around the outside of the opening in the fuselage skin. The AOA sensor and overlay are therefore inserted together into the opening, with the holes in the overlay aligned with the holes in the fuselage skin, and affixed in place by 15 screws. A cover, also featuring a center cutout for the AOA vane, is then placed over the entire area and secured by 6 bolts, corresponding to 6 bolt holes on the fuselage skin. The diagram below shows all these parts and their relationships to one another, identified by numbers that match to the key in the image caption.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*a2YUqC07drOo8EsZcU9BDA.png" /><figcaption>1 — Fuselage skin. 2 — Electrical connector. 3 — overlay. 4 — Overlay-to-fuselage attachment screws. 5 — cover. 6 — Cover attachment screws. 7 — Overlay-to-sensor attachment screws. 8 — washer. 9 — spacer. 10 — AOA sensor guide pins. 11 — washer. 12 — nut. 13 — AOA sensor. 14 — washer. (MAK)</figcaption></figure><p>It must be noted that while the fuselage skin, the cover, and the overlay are all manufactured by UAC, the AOA sensor itself — like all the SSJ-100’s avionics — is an off-the-shelf Thales product. Therefore, UAC had to decide at the design stage how to incorporate the Thales AOA sensors in a manner that would support proper functioning of the sensor, comply with safety regulations, and permit replacement of the unit by maintenance personnel.</p><p>Perhaps the earliest link in the chain of events leading to the accident was UAC’s decision not to establish specific guidelines for where the first of the 15 attachment holes on the fuselage panel should be drilled. As a result, the exact positions of the attachment holes were different on every individual fuselage, even though the number of holes and the spacing between them was always the same. But that meant that the corresponding holes on the overlays couldn’t be drilled systematically either. After the five attachment holes for the sensor housing were drilled into the overlay, the 15 outer attachment holes had to be drilled in such a way that when they were lined up with the 15 corresponding holes on the fuselage, the AOA sensor housing would also be aligned with the aircraft’s “structural horizontal.” This is because tilting the unit even slightly off its intended axis will introduce a systematic error across all measured angle of attack values. Since the angle of attack is (in simplified terms*) the angle of the airflow relative to the aircraft’s horizontal axis, the “zero point” of the vane’s range of motion must be aligned with that axis or else the vane will measure against the wrong baseline.</p><blockquote>*Technically, wing angle of attack and fuselage angle of attack are slightly different things. But for the purposes of this explanation, we don’t need to get into that.</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6ELLkZZvrWW2x8ufMIZS1Q.png" /><figcaption>Using an optical quadrant to establish the required angle of the guide pin axis. (MAK)</figcaption></figure><p>Considering the fact that the attachment holes were aligned slightly differently on every fuselage, while the AOA sensors had to be installed at the exact same angle every time, UAC ended up having to make custom overlays not only for each aircraft, but for each installation location on each aircraft as well. UAC did this by drilling the 15 attachment holes around the edge of the overlay first, then screwing the overlay into place on the fuselage. Then, once the overlay was in place, an optical guide device was used to determine where to drill two small holes designed to accommodate a pair of “guide pins” on the sensor housing. The purpose of the guide pins is to ensure that there is only one possible way to attach the overlay to the sensor. Using the optical guide device, the machinists had to ensure that the axis formed by the two guide pin holes would be offset from the aircraft’s vertical axis by exactly 8˚42’ (±6’) counterclockwise on the left side of the plane and clockwise on the right side. Only with the guide pin axis at this angle will the AOA sensor read zero when the angle of attack is zero degrees.</p><p>Once the guide pin holes were drilled, the optical guide device was used again to the drill the five attachment holes for the sensor housing in the correct positions relative to the guide pin holes.</p><p>Of course, if the positions of the attachment holes on the fuselage had been standardized from the start, then the overlays could have been mass-produced. Instead, this process ensured that no two overlays had exactly the same relative alignment between the sensor housing attachment holes and the fuselage attachment holes.</p><p>This might not have been the most optimal manufacturing technique, but it shouldn’t have presented any maintenance or supply issues <em>per se</em>. The overlay is a static part that should last many times longer than the aircraft itself, so there should be no need for maintenance personnel to ever replace it. However, the process of replacing the AOA sensor necessarily involves removing the overlay and then reinstalling it later, which is where things start to get problematic.</p><p>At some point during the design process, it must have been realized that while the guide pin holes ensure that there is only one way to attach the overlay to the sensor, there are still 15 different ways to attach the overlay-sensor assembly to the fuselage. If you put the overlay up against the fuselage and line up the holes, that means nothing, because if you rotate it 24 degrees left or right, the holes will line up again, and after a further 24 degrees they line up yet again, and so on and so forth, all the way around the circumference of the assembly. The most reliable solution to this problem would be to design some kind of asymmetry in the pattern of attachment holes, such that the holes would only line up with the overlay in the correct orientation. But that was not done in this case. Instead, UAC’s solution was to add a step in the maintenance manual procedure for removing the sensor, calling for the technician to draw a mark across the overlay and the adjacent fuselage skin with a permanent marker prior to removing the overlay (as seen below). That way, whoever reinstalled the overlay could install it in its original orientation simply by lining up the two halves of the mark.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mIjZybcMTfdOY5b_CH6Mew.png" /><figcaption>The red mark used for alignment purposes can be seen at right. Note how it’s drawn across both the overlay and the fuselage skin. Some other things to note: the cover is off; the black stuff is sealant; and the rotation angle of the vane is arbitrary and unrelated to the overall sensor alignment. Can you see the 15 overlay-to-fuselage attachment points, the five overlay-to-sensor attachment points, and the two guide pins? (MAK)</figcaption></figure><p>In 2013, after producing about 20 aircraft, UAC began applying this mark during the manufacturing stage. The maintenance procedure was concurrently revised to require technicians to re-draw the mark, even if it was already present, in order to prevent it from fading.</p><p>Although this was a crude solution to the problem, it proved fairly effective in practice simply because the instructions were easy to follow and it was obvious whether the two halves of the mark were aligned or not. But the question necessarily arises: what would happen if someone tried to install an overlay onto the wrong aircraft, or the wrong position on the right aircraft?</p><p>Because the overlays are unique to each installation location, installing them in another location where the orientation of the attachment holes is slightly different usually makes it impossible to line up the AOA sensor with the aircraft’s horizontal axis.</p><p>After the accident, the MAK carried out extensive testing on several SSJ-100s in order to determine what would happen if technicians swapped the left and right overlays, installing the left overlay on the right side and vice versa. They found, first of all, that it was possible to swap the overlays in this manner without causing the AOA sensor to obviously point the wrong way, simply by rotating the overlay 180 degrees before attaching the AOA sensor to it. Subsequently, the sensor-overlay assembly could be installed into the fuselage with the vane pointing in generally the right direction, but with an offset equal to the number of degrees difference between the attachment hole positions on the overlay’s intended location and its actual installation location. This could be anywhere from zero to 24 degrees and was unique on each aircraft. Furthermore, the difference in the size of the offset between the left and right sides was never more than about 3 degrees.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*c7yrSJ0NZA8uWlc3V9lflw.png" /><figcaption>A superposition of the left and right overlays, showing the left overlay placed on top of the right overlay from aircraft serial number 95032. it is possible to get the sensor guide pin line to within 4 degrees of the correct position, but the marks won’t align.</figcaption></figure><p>On some aircraft, this kind of mismatch was highly improbable because the marks couldn’t be aligned without rotating the AOA sensor too far from the correct position. If the vane is pointing in completely the wrong direction, most technicians will immediately recognize that something is wrong. And on some aircraft, the marks could not be aligned at all with the overlay in any orientation. But the MAK discovered that on certain aircraft, it was possible to align the marks and the attachment holes at the same time with the AOA sensor oriented close to the normal position. Whether this was the case entirely depended on where the marks on each side had been arbitrarily drawn by whoever first applied them.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*nBCJ0LbsCFMUzZBvdlyuvw.png" /><figcaption>This superposition of two AOA sensor overlays from aircraft RA-89032 shows it is possible to align the marks with the right overlay on the left side of aircraft 95032, resulting in a guide pin line error of +27˚.</figcaption></figure><p>In the process, the MAK also discovered that similar results could be achieved by installing an overlay face down instead of face up. The inner face of the overlay is covered with gray enamel while the outer face is covered with yellow primer and black sealant, providing a distinctive clue about the correct orientation, but there was nothing physically stopping someone from installing it the wrong way around. A technician attempting to install it this way will discover that there is no mark on the overlay to align with the mark on the fuselage. Attempting to install the overlay anyway will offset the sensor from the aircraft’s horizontal axis because the overlay is asymmetrical.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*OXLQ5fC73ErVaOMxmmVpGg.png" /><figcaption>The effects of inverting the left overlay from aircraft RA-89029. On top: correct installation. On bottom: effects of installing the overlay inverted.</figcaption></figure><p>In order to exclude the possibility of installing the overlays on the wrong side of the aircraft, the maintenance manual carried a warning: <em>“ATTENTION: Reinstall the overlay only onto the location on the fuselage skin from which it was taken.”</em> However, this procedure couldn’t prevent technicians from installing the overlay inside-out. And as you’re probably guessing, it was fallible in other ways as well.</p><p>During research for this article, I sought to answer a question not posed by the MAK’s report: namely, whether the design of the AOA sensor installation complies with certification requirements. Since the FAA, EASA, and Russia’s Federal Air Transport Agency all have virtually identical regulations, I used the publicly accessible databases of the FAA and EASA in order to find out — keeping in mind that EASA certified the SSJ-100 in 2012 and revoked that certification in 2022.</p><p>FAA and EASA regulations both contain the following language: <em>“Each element of each flight control system must be designed, or distinctively and permanently marked, to minimize the probability of incorrect assembly that could result in failure or malfunctioning of the system. The applicant may use distinctive and permanent marking only where design means are impractical.” </em>(FAR 25.671)</p><p>As someone not trained in aircraft certification, I can’t be certain whether the angle of attack sensors on a fly-by-wire aircraft count as part of the flight control system. However, it is true that they provide data that forms part of the aggregated command signal sent to the flight control surfaces by the fly-by-wire system. Furthermore, the current FAA advisory circular describing how to comply with FAR 25.671 states that compliance for fly-by-wire aircraft includes an “evaluation of command signal integrity.” The circular lists factors that can adversely affect that integrity, including “corrupted sensor signals” and “frozen or erroneous values.” Therefore, in my unprofessional opinion, it seems plausible that regulators may consider the AOA sensors to be a flight control system element subject to FAR 25.671, and that measures to “minimize the probability of incorrect assembly” must be taken if that incorrect assembly “could result in a… malfunctioning of the system.”</p><p>If compliance with FAR 25.671 was required, then the preferred method of compliance was a design solution. However, there was no design element preventing incorrect assembly. Instead, UAC used markings, but it’s debatable whether these markings were “distinctive” or “permanent.” These markings did reduce the probability of incorrect assembly, but did they “minimize” it? I would argue that marking the overlays with the words “left,” “right,” and “this side down” would have been a lot better.</p><p>Most likely, UAC’s strongest argument for compliance was that the maintenance manual warning (“reinstall the overlay only onto the location on the fuselage skin from which it was taken”) effectively minimized the probability of incorrect assembly when implemented in combination with the marking system. But it turns out that under the conditions of modern Russian aviation, the assumptions underpinning that assessment were starting to erode.</p><p>Let’s resume the story on 20 March 2024, when RA-89029 was brought in for the 1C+5C check. For reasons that are left unstated in the report, Gazpromavia wanted to remove the two primary AOA sensors from this aircraft. Perhaps there was a problem with the sensors and they needed to be removed from service — we don’t really know. All we do know is that the sensors were given back to Gazpromavia and were never reinstalled on an aircraft.</p><p>Under normal conditions, maintenance technicians would retrieve two new AOA sensors from the stores, then replace the existing sensors one at a time. This ensures that the overlays are always put back where they came from, because there is only one spot to put them at any given moment.</p><p>But in this case, there was a complication: according to the MAK report, neither Gazpromavia nor the MOC had any spare AOA sensors for the SSJ-100 in stock. The reason for this shortage is left unstated, but the truth is written between the lines. Most likely, neither company was able to acquire surplus supply of a part that that was manufactured in France and was forbidden for export to Russia due to EU sanctions.</p><p>Without any new AOA sensors available to replace those removed from RA-89029, Gazpromavia and/or the Lukhovitsy MOC devised a scheme to keep the work on schedule. (It’s not entirely clear from the report whose idea this was, or whether it was an agreement between both companies.) The plan was to retain RA-89029 at the MOC until the next airplane came in for routine inspections, at which point technicians would remove the AOA sensors from that airplane and install them on RA-89029, allowing the latter to return to service. The second airplane, RA-89049, would then undergo the planned inspection and servicing, until the arrival of the next airplane, RA-89018. The sensors would then be removed from RA-89018 and installed on RA-89049, allowing it to depart as well. In other words, they arranged a bucket brigade, only with airplanes instead of firefighters and AOA sensors instead of buckets.</p><p>It’s not clear from the report whether Gazpromavia intended for this bucket brigade to continue beyond RA-89018. However, my interpretation is that they always planned for it to end there. At the time the report was published in July 2025, RA-89018 was still parked at the MOC, suggesting that this aircraft has been withdrawn from service and is possibly being stripped for parts. Furthermore, current sources list only 7 aircraft in Gazpromavia’s SSJ-100 fleet, as opposed to 9 aircraft before the accident.</p><p>The events that occurred during this “bucket brigade” involved a cast of five characters. These individuals are identified in this article as follows:</p><p>· Technician 1: A 28-year-old level 4 technician who had been working for RAC MiG since the age of 16, except for a year in the armed forces.</p><p>· Technician 2: A 49-year-old level 6 technician, who originally qualified in 1994 and briefly worked as a technician, left for two decades, and returned in 2015 to work for RAC MiG.</p><p>· Technician 3: A 36-year-old level 4 technician who had been working at RAC MiG since 2007.</p><p>· Technician 4: A 27-year-old level 4 technician who had worked for RAC MiG since 2016.</p><p>· The Section Foreman: A 30-year-old who had worked for RAC MiG since 2012, except for a year in the armed forces.</p><p>Between 20 March and 22 March 2024, Technician 1 removed one AOA sensor from RA-89029 under the supervision of Technician 2, who was qualified to provide oversight. Later, the other AOA sensor was removed by Technician 3 under the supervision of the Section Foreman.</p><p>On 02 May, after RA-89049 arrived at the MOC, Technician 4 removed both AOA sensors from that aircraft, under supervision of the Section Foreman, and transferred them to stores. The overlays were presumably placed in stores at that time as well. Because both sensors were needed for installation on RA-89029, and RA-89018 hadn’t arrived yet, the usual practice of only removing one overlay at a time could not be followed.</p><p>On 04 May, Technician 2, under supervision of the Section Foreman, installed both AOA sensors from RA-89049 onto RA-89029. The installation would have involved retrieving the AOA sensors from stores; mating each one to the correct overlay; applying paste to the attachment screws; greasing the washers; re-applying primer, enamel, and sealant; hooking up the electrical connection; attaching the overlay to the fuselage; applying more sealant; and installing the cover. The full procedure from the maintenance manual is shown below.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/848/1*lU_-3BfFvbfPifp-QiqfXw.png" /><figcaption>The maintenance manual procedure for reinstalling an SSJ-100 AOA sensor. (MAK)</figcaption></figure><p>On 06 May, RA-89029 was declared fit for service, and two pilots arrived to reposition it to Vnukovo. But data later showed that as the aircraft sped down the runway, the angle of attack provided to the №1 air data system by the left AOA sensor suddenly spiked to values as high as 7.2˚. This was obviously impossible, because during the takeoff roll prior to rotation, the pitch angle and the flight path angle are both zero, and therefore the angle of attack should be zero as well. In fact, investigators would later determine that the AOA values provided by ADS 1 were systematically too high throughout the entire flight.</p><p>During the climb, several fault messages appeared on the Electronic Warning Display (EWD) in the cockpit, including NAV ADS 1 FAULT, NAV BARO REF DISAGREE, and NAV ALT DISAGREE.</p><p>While each individual set of instruments receives data from a single air data system, the fly-by-wire system uses parameters consolidated from all three systems in order to ensure redundancy. The flight computers constantly compare the outputs of the three data sources, and if one system produces parameters that differ considerably from the other two, then the faulty ADS will be isolated from the fly-by-wire system to contain the erroneous data. Rejection of an ADS in this manner generates a NAV ADS (1)(2)(3) FAULT on the EWD. The exact rejection criteria for airspeed and angle of attack will be discussed in Part 3.</p><p>On RA-89029, the erroneously high AOA reading from ADS 1 resulted in an improper correction being applied to the №1 static pressure, which in turn caused a difference in the barometric altitude data being provided by ADS 1. This resulted in the additional alert messages “NAV BARO REF DISAGREE” and “NAV ALT DISAGREE.”</p><p>As soon as the difference in AOA or altitude between ADS 1 and the average of all three ADSs exceeded a threshold value, ADS 1 was rejected by the flight computer and its data were no longer used to develop control surface commands. In response to the alert messages, the crew used the captain’s air data source selector to change the air data source for his instruments from ADS 1 to ADS 3, and then turned ADS 1 off. No further problems were encountered and the flight was continued to its destination.</p><p>After the aircraft arrived at Vnukovo, technicians carried out diagnostic maintenance. According to the records of this maintenance, the failure did not reappear after rebooting the computers. However, the MAK found that the angle of attack data from ADS 1 had a systematic error throughout the entire flight of approximately +8.2 to +8.3 degrees, which is more likely the result of an installation error than a computer error. When investigators examined the airplane, they found all the AOA sensors installed correctly — but while testing possible scenarios, they discovered that if the left AOA sensor overlay from this aircraft was installed face down instead of face up, the sensor vane would be displaced from the aircraft’s horizontal axis by +17 degrees. After the correction algorithms were applied, the total angle of attack error with the sensor in this position would come out to about 8.5˚ ±0.2˚. (See previous diagram.)</p><p>The MAK also noted that the manner of sealant application on the left and right primary AOA sensors on RA-89029 was very different, despite the fact that both were officially installed by Technician 2. On this basis, the MAK speculated that the left sensor may in fact have been installed by someone else whose role was not documented. The report doesn’t say whether this means that a person other than Technician 2 mistakenly installed the overlay face down, or whether the removal and reinstallation process was repeated during the troubleshooting at Vnukovo. My assumption is the latter, because the overlay must have been removed and then reinstalled correctly before the next flight, or the problem would have reoccurred. The technicians who did so might not have even realized anything was wrong, because simply following the procedure in the maintenance manual for removal and reinstallation of the sensor would have solved the problem even if they were unaware of it. The procedure also includes applying new sealant, which could explain why the sealant on the left overlay seemed to have been applied by a different person. For whatever reason, this work was not recorded in the troubleshooting log, and rebooting the computers was listed as the corrective action. The incorrect installation was not identified or reported.</p><p>Following the 06 May departure of RA-89029, its sister ship RA-89049 underwent a battery of checks, designated 2A+4A+1C+2C+5C. During this time, it sat there with no primary AOA sensors and both overlays removed.</p><p>Records from the part stores showed that on 06 July, Technician 2 went to the stores and retrieved two “AOA sensor hatches.” Officially this refers to the sensor covers, which were presumably removed from RA-89049 back in May, alongside the overlays. There was no record of anyone retrieving the overlays themselves. Also, the separate parts catalog stated that the covers were kept in stores until 08 July, two days after Technician 2 supposedly retrieved them. This discrepancy was not resolved.<br> On 07 July, after the arrival of RA-89018, Technician 1 removed both AOA sensors from that aircraft under the supervision of Technician 2 and took them to stores.</p><p>On 08 July, records showed that Technician 1 obtained the work order pertaining to the installation of two AOA sensors on RA-89049. Documentation also showed that Technician 2 went to the stores and retrieved the two AOA sensors removed from RA-89018 the previous day. However, only one AOA sensor was ever signed for.</p><p>Technician 1 stated that he installed only the left AOA sensor on RA-89049 on that day, under supervision of Technician 2. He stated that the marks lined up and he had no difficulty installing the overlay.</p><p>An attachment to the work order stated that both AOA sensors were installed that day, but this was false. A further breach of protocol occurred as neither technician returned the second AOA sensor nor any of the tools to stores at the end of the work day.</p><p>On 09 July, Technician 1 was absent from work. Even though the work order listed Technician 1 as the responsible party, Technician 2 decided to finish the work himself. After obtaining the required parts, he applied sealant to the left AOA sensor, then attempted to install the right sensor. However, he stated that he had difficulty installing the overlay because there were multiple marks in different colors, and it wasn’t obvious which marks he was supposed to line up. Eventually he was able to align two black marks, after which he completed the installation successfully.</p><p>The MAK would later discover that Technicians 1 and 2 installed the left and right overlays on the wrong sides of the aircraft. The inherent fallibility of the marking procedure allowed them to align the marks even though the overlays were not in the correct positions. However, the investigators were unable to determine where and when the mix-up occurred — whether it was before the overlays were submitted to the stores, while in storage, or after they were retrieved. Apparently no information about the storage of the overlays was ever written down, nor is there any evidence that steps were taken to ensure that each overlay was reinstalled in the same position from which it was taken, as required by the maintenance manual.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*l3U0ZkTiNr3alxSrJfF-Pg.png" /><figcaption>After the accident, a portion of the right overlay was recovered still attached to a piece of the left fuselage. The red marks were aligned, proving Technician 1’s story. (MAK)</figcaption></figure><p>On 10 July, Technician 1 returned to work to find that Technician 2 had completed the installation. It doesn’t appear that Technician 2 was supervised by anyone, nor was he officially recorded as the performer of the work.</p><p>The MOC’s official standards document stated that any “installation and adjustment work” should be subject to a post-work quality inspection. However, the associated task card was never filled out and no inspection was ever performed. The inspection procedure is not described in the MAK report, but if it included a check of the sensor installation angle — which I should hope it does — then the mistake would have been detected.</p><p>One topic that the MAK report doesn’t cover is the training received by the technicians. The report points out that out of four AOA sensors installed by this team in 2024, three were installed incorrectly. Nevertheless, investigators found no record of any previous cases of systematically erroneous angle of attack indications on the SSJ-100, which suggests that these installation errors had never been made prior to RA-89029. Furthermore, RA-89049 was only the 25th aircraft ever to undergo servicing at the Lukhovitsy MOC. All of these facts raise questions about how the maintenance staff were retrained when the facility began maintaining SSJ-100s in 2021, but as of this writing, none of those questions have adequate answers.</p><p>In any case, unaware that they had made a potentially catastrophic error, the maintenance crew finished preparing the aircraft on 11 July, and the following day it was released for service. Despite the technicians’ successful attempts to align the markings, the left AOA vane was in fact offset from the aircraft’s structural horizontal by +9 degrees, while the right AOA vane was offset by +11–12 degrees, resulting in a true angle of attack error of approximately +4–5 and +5–7 degrees respectively.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ln9nx8vk2XjpAT8b7CA4pQ.png" /></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0MZiA2nqx5VHm6znjdTLSw.png" /><figcaption>How the left and right overlays were installed on the opposite sides of RA-89049. Note: The bottom left diagram should say “right position,” not “left position.” (MAK)</figcaption></figure><p>With the covers placed over the overlays, it would have been all but impossible to notice that the AOA sensors were installed incorrectly. The MAK even tracked down a photograph of RA-89049, taken on the 12th of July 2024, but when they tried to test whether the AOA sensor installation angle could be determined from the photo, they found that this was impossible. Because the AOA vanes can rotate freely into any position in their ±40 degree operating range during pushback and taxi, the position of the vane as viewed by an outside observer has no detectable relationship to the sensor installation angle. In other words, there was no way for anyone to catch the mistake until the airplane started moving.</p><p>And so the stage was set for an epic battle between man and machine — one in which neither would emerge the winner.</p><p>◊◊◊</p><h3><strong>Part 3: The Men and the Machine</strong></h3><p>Around midday on 12 July, an unsuspecting flight crew arrived at Tretyakovo Airport to reposition RA-89049 to Vnukovo Airport.</p><p>In command was 53-year-old Captain Yevgeniy Bulavko, an experienced pilot who had risen from the rank of navigator, accumulating 13,220 flight hours in the process, including over 5,000 on the SSJ-100.</p><p>His first officer that day was 53-year-old Vladislav Kharlamov, whose 12,518 total hours and 4,000 on the SSJ-100 made him almost as experienced as Captain Bulavko. Neither pilot had any record of training difficulties, and they had both successfully completed many emergency drills involving unreliable air data during recurrent training. There was no evidence of any discrepancies in Gazpromavia’s training program or in the pilots’ career progression.</p><p>Also on board was a third individual, identified as flight attendant Maksim Lukmanov. Why he was on this flight is not stated in the final report nor in any news reports that I was able to locate. I’m sure there was a good reason; I just don’t know what it was.</p><p>The three men boarded the aircraft at around 14:15, after which the pilots completed all pre-flight checks in accordance with standard operating procedures. The crew also obtained the latest weather information, conducted a detailed pre-flight briefing, started the engines, and ran through the full battery of control checks. All control surfaces responded normally and no instrument indications suggested any abnormality.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*k57AwUAnWHjzVQg0jPAQjA.png" /><figcaption>Photograph of RA-89049 taken during pushback on the day of the accident. (MAK)</figcaption></figure><p>At 14:48, RA-89049 departed the stand, operating as flight 9608. The crew taxied to the head of the southeast-facing runway 10, where they set the stabilizer to the correct takeoff position and entered the calculated takeoff speeds into the flight management system. An initial climb altitude of 5,000 feet was also set.</p><p>At 14:52:58, the Tretyakovo air traffic manager cleared them for takeoff. Captain Bulavko handed control to First Officer Kharlamov, who acknowledged. He then set engine thrust to the calculated takeoff setting and engaged the autothrottle. “Flexible takeoff thrust 86% set,” Bulavko called out.</p><p>As the airplane accelerated down the runway, the airspeed indicators came alive, followed by the angle of attack indicators at 60 knots. But where the AOA should have read zero, the left AOA spiked to 3.8˚, while the right jumped to 4.8˚. These values increased to 4.2˚ and 5.9˚, respectively, as the airplane accelerated. However, monitoring the angle of attack indications isn’t part of the normal takeoff instrument scan, nor are the indications particularly eye-catching, so neither pilot noticed.</p><p>At 100 knots, Captain Bulavko called out their airspeed, followed five seconds later by “V1, rotate.” First Officer Kharlamov pulled back on his side stick and the nose rose into the air, followed by the main wheels. “Positive climb,” Bulavko declared.</p><p>“Gear up,” Kharlamov replied.</p><p>“Gear up,” Bulavko acknowledged, retracting the landing gear.</p><p>Eleven seconds after liftoff, at a height of 445 ft, Kharlamov called for the autopilot, and Bulavko flicked it on, calling out, “Autopilot engaged, check.”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4o79CbnpEM-jdVxCR77wgg.png" /><figcaption>Annotated flight path, part 1: takeoff to autopilot engagements. (MAK)</figcaption></figure><p>Although they didn’t know it yet, the flight was about to experience a rapidly cascading sequence of events that requires considerable technical background to understand. Within 5 minutes, it would all be over — but first, we need to meet the math behind the machine.</p><p>◊◊◊</p><p>The SSJ-100 fly-by-wire system works in much the same way as the standard Airbus fly-by-wire system. My article on Aeroflot 1492 goes into more detail about how fly-by-wire systems work in general; for this article, I’ll briefly describe the concept before getting into the details relevant to this story.</p><p>When the pilot of the SSJ-100 deflects the side stick left or right, for instance, they are commanding a particular roll <em>rate.</em> The flight computers then calculate how to deflect the ailerons in order to achieve that rate under the current conditions. If the airspeed is high, less aileron deflection is needed; conversely, more is needed if the speed is low — but the pilot doesn’t have to worry about this, because the computers ensure that the response of the aircraft to a given input is always about the same.</p><p>Deflecting the side stick forward or aft commands a particular load factor. When a moving vehicle changes direction suddenly, you feel a pull, which is a “load,” often expressed in terms of G-force equivalent. In straight and level flight, the load factor is 1, or 1 G — normal earth gravity. When an airplane transitions to a climb, the load factor increases, which the occupants experience as a force pressing them down into their seats. The faster the transition, the higher the load factor. Therefore, if the pilot deflects the side stick aft and holds it there, the airplane will pitch upward continuously in order to maintain a constant load factor greater than 1. When the pilot relaxes the side stick, the pitch will stop changing. If they now want to reduce the pitch, the pilot should push forward on the side stick to command a negative load factor. The larger the side stick deflection, the larger the load factor, and the larger the pitch rate.</p><p>The system also incorporates flight envelope protections that include both soft and hard limits on airspeed, angle of attack, pitch angle, bank angle, and load factor. For example, if the pilot holds the side stick all the way to the left, the bank angle will increase up to a hard limit, but no further. If the pilot relaxes the side stick, the bank angle will decrease and stabilize at a lower soft limit. Active deflection of the side stick is required to achieve bank angles above the soft limit and below the hard limit.</p><p>By contrast, the high airspeed limiting function doesn’t have a soft limit. Instead, if the airspeed increases above the maximum operating speed of 308 knots, or VMO, the system will intervene by automatically deploying the speed brakes, which pop up from the wings to increase drag and reduce speed.</p><p>The angle of attack limiting function is more complex. As the angle of attack increases, the function activates in stages corresponding to certain thresholds, called “alpha linear,” “alpha prot,” “alpha floor,” and “alpha limit.”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BciPnuPkcmbUYnOfE0y_rQ.png" /><figcaption>The angles of attack used by the AOA limiting system. CL = lift coefficient. (MAK)</figcaption></figure><p>Alpha linear is the AOA above which the derivative of the lift coefficient becomes non-linear. You don’t need to know what that means, but it is worth noting as the point where an angle-of-attack-related coefficient begins to be applied to the pitch command signal for purposes of stability augmentation only.</p><p>Alpha prot, short for “protection,” is the point at which the angle of attack limiting function kicks in. This function applies a reducing coefficient to the pitch command in order to prevent the angle of attack from reaching the hard limit, which is alpha limit. The size of the coefficient is whatever the function needs it to be in order to accomplish that goal, taking into account factors such as pitch rate.</p><p>Alpha limit, as I just said, is the absolute maximum, equivalent to “alpha max” on the Airbus A320. The pilot can theoretically achieve alpha limit only by holding the side stick fully aft, and no matter how long they hold it there, the angle of attack limiting function will not allow the AOA to increase any further. Releasing the side stick will cause the angle of attack to reduce to alpha prot.</p><p>Alpha limit is defined as one degree below the angle at which the stall warning will activate, which is itself some distance below the actual stall angle of attack. The value of alpha limit changes depending on the flap setting and Mach number (speed expressed as a percentage of the local speed of sound), with the lowest values of alpha limit occurring with flaps retracted and a high Mach number. This is because these two factors reduce the stall AOA.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S54LVPYml48WYV0xHjxMaA.png" /><figcaption>This excerpted flight data from RA-89049 shows how the values of alpha limit and alpha prot decrease when the flaps are retracted. (MAK)</figcaption></figure><p>Now, you might have noticed that I said alpha limit can only be reached “theoretically.” That’s because the actual limit value used by the angle of attack limiting function is not actually alpha limit. According to the MAK report, a margin exists between the actual highest allowable angle of attack and alpha limit, depending on certain dynamic factors not enumerated therein. Presumably this is to prevent the AOA from exceeding alpha limit in case of rapid aircraft movements that exceed the response capabilities of the limiting function.</p><p>Lastly, alpha floor is an angle of attack between alpha prot and alpha limit where a separate function automatically commands an increase in engine thrust. The purpose of this function is to increase the aircraft’s energy state, helping reduce the AOA required to maintain lift. However, this function doesn’t play a direct role in this story.</p><p>The authority of the flight envelope protections is incontrovertible when the fly-by-wire system is in Normal Mode; the pilot cannot override them. If the data that the fly-by-wire system uses to support these functions becomes invalid or unavailable, then the system may switch to Direct Mode, either automatically or by manual selection. In Direct Mode, the flight envelope protections are unavailable and a direct relationship is established between side stick deflection and control surface deflection. Switching to Direct Mode is generally considered an option of last resort as it makes the aircraft considerably more difficult to fly.</p><p>◊◊◊</p><p>I also want to discuss how the pitch command signal is assembled in Normal Mode. By pitch command signal I mean the electronic signal that actually gets sent to the actuator control units to tell them how much to deflect the elevators. The components of this signal include but are not limited to:</p><p>· A coefficient (positive or negative) derived from the side stick position;</p><p>· The load factor commanded by the side stick;</p><p>· Positional feedback, in order to make the command proportionate to the existing load factor and pitch rate;</p><p>· Angle of attack feedback when the angle of attack is above alpha prot, in order to prevent the AOA from reaching alpha limit;</p><p>· And pitch feedback from the high pitch limiting function.</p><p>Collectively, the signal components ensure that the airplane reacts to the pilot’s inputs in the desired manner, without overshooting or undershooting, and without exceeding any flight envelope limitations.</p><p>The above components are only those involved in deflecting the elevators. Pitch control is also effectuated by the trimmable horizontal stabilizer, which determines the pitch and speed combination at which the airplane is stable when no control inputs are being applied. A separate algorithm causes the stabilizer to “follow” the elevators using a so-called integral loop in order to ensure that the airplane remains at the last commanded pitch when the pilot relaxes the side stick.</p><p>The fly-by-wire system on an aircraft like the SSJ-100 doesn’t rely on a single sensor, like Boeing’s infamous MCAS did. Instead, as I mentioned earlier, it integrates parameters from all three air data systems. In the case of angle of attack, the system uses a “consolidated AOA” equal to the average of the AOA outputs from ADS 1, 2, and 3. The value of each individual output is then compared to the median value, and if the difference exceeds a certain threshold, the data source is rejected as faulty, a NAV ADS (1)(2)(3) FAULT message appears on the EWD, and the fly-by-wire system continues to operate using a consolidated AOA equal to the average of the remaining two data sources. The exact rejection threshold decreases as airspeed increases, from 7.5 degrees at 100 kts to 3.0 degrees at the maximum operating speed (VMO). This rather large allowable variance is necessary in order to account for local angle of attack differences that can occur while maneuvering; for example, if the aircraft is in a sideslip.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mYZeCBqMCggmzNaHJZU7QQ.png" /><figcaption>The maximum difference between an AOA indication and the median AOA value as a function of airspeed. The orange line shows the normal threshold; the blue line shows the threshold if one ADS has already been rejected. (MAK)</figcaption></figure><p>Similarly, the fly-by-wire system uses a consolidated airspeed value equal to the average of the airspeed values provided by the three air data systems. If the difference between any two airspeed values exceeds 10 knots, then one of two things can happen.</p><p>If, say, ADS 1 is providing an airspeed more than 10 kts different from both ADS 2 and ADS 3, then ADS 1 is identified as faulty, its data are rejected, a NAV ADS 1 FAULT message appears on the EWD, and the fly-by-wire system switches to using the average of the two remaining airspeeds. This is what happened on RA-89029, and it’s called an “unambiguous fault.” But if, say, ADS 1 is more than 10 kts different from ADS 3, but ADS 2 is within 10 kts of both ADS 1 and ADS 3, then this is considered an “ambiguous fault” because the fly-by-wire system doesn’t know which ADS is faulty. In that scenario, a NAV ADS DISAGREE message appears on the EWD, prompting the crew to apply the “unreliable airspeed” procedure, which provides them with tools to determine which ADS, if any, is faulty.</p><p>Because this is really important, I’ll provide a more concrete example (courtesy of the MAK): if the outputs of ADS 1, 2, and 3 are 200 kts, 212 kts, and 215 kts respectively, then that’s an <em>unambiguous fault</em> with ADS 1. And if the outputs are 200 kts, 209 kts, and 211 kts, respectively, then that’s an <em>ambiguous fault</em> and flight crew action is required to identify the culprit.</p><p>There is also a special logic that kicks in if none of the three ADS airspeeds are within 10 kts of any of the others, but that’s outside the scope of this article.</p><p>◊◊◊</p><p>Returning to flight 9608, at 14:53:49 the autopilot was engaged. The autopilot has lateral and vertical channels that run separate modes, some of which are coupled to the autothrottle. At the moment of engagement, the autopilot’s lateral channel was in LNAV mode, which commands the airplane to follow the track programmed into the flight management system — in this case, the RILPO 1B Standard Instrument Departure. Seconds later, the vertical mode was set to Climb (CLB), which is a speed-on-pitch mode, meaning that the autopilot will maintain the airspeed selected by the crew by increasing pitch to slow down and decreasing pitch to speed up, while thrust remains constant. In Climb mode, the autothrottle automatically enters thrust hold mode (THR) with the engines at climb power.</p><p>It should be noted that the SSJ-100, like modern Airbus models, has thrust levers that act as engine operating regime selectors when the autothrottle is engaged. The flight crew simply places the levers into the desired regime — idle, cruise, climb, flex takeoff, max climb, takeoff/go-around (TOGA), or max thrust* — and the autothrottle determines how much thrust is needed, within the boundaries of the selected regime.</p><p><em>*Note: This regime is unique to the SSJ-100 and does not appear on any Airbus.</em></p><p>Moments before engaging CLB mode, Captain Bulavko said, “We agreed to reduce the vertical speed, Vlad.”</p><p>“Ah, got it, right now,” First Officer Kharlamov replied.</p><p>“Well, switch to climb and rein in the speed,” said Bulavko.</p><p>“Climb,” Kharlamov called out as he set climb mode. Seconds later, he added, “Speed.”</p><p>“Selected,” Bulavko announced, setting an airspeed of 148 knots using the flight control panel.</p><p>“Speed, climb,” Kharlamov repeated.</p><p>“Put 1,500, vertical speed,” said Bulavko.</p><p>“Vertical 1,500 set,” said Kharlamov. He reached over and switched the autopilot’s vertical mode from Climb to Vertical Speed (V/S).</p><p>In Vertical Speed mode, the autopilot pitches up or down to maintain a selected climb or descent rate — in this case, 1,500 feet per minute — while the autothrottle switches to speed hold mode (SPD) and modifies engine thrust as required to achieve the selected airspeed.</p><p>“Oh, perfect, and what are we climbing to?” Bulavko asked.</p><p>At that moment, a chime sounded, and a message appeared on the EWD: “DOORS FWD (L) HATCH NOT CLOSED.” The procedure associated with this message, according to the pilots’ Quick Reference Handbook (QRH), is to check whether the airplane is pressurizing properly, and if it is, to disregard the message.</p><p>“Left door hatch(er) not closed,” Bulavko said in English.</p><p>“Check,” said Kharlamov.</p><p>“What the hell do we have here?” Bulavko mused.</p><p>A few lines of unintelligible dialogue followed, after which the crew dismissed the alert. The airplane was pressurizing normally, so the caution was evidently erroneous. The cause of the false door open caution is not explained in the MAK report, but small glitches like this are not uncommon after major maintenance.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*asix3lX5wg57cgC1KGg3nA.png" /><figcaption>Annotated flight path, part 2: autopilot engagement to initial acceleration. (MAK)</figcaption></figure><p>As the aircraft proceeded through its left turn after takeoff, Captain Bulavko told First Officer Kharlamov to switch the autopilot’s lateral channel to Heading mode (HDG) in anticipation of instructions from air traffic control. Kharlamov engaged heading mode and selected a heading of 004 degrees. A short time later, he reduced the selected vertical speed to about 1,000 feet per minute in order to begin accelerating so they could retract the flaps. Moments later, at 14:54:56, Kharlamov called, “Flaps 1.”</p><p>“Flaps 1,” Bulavko repeated as he moved the flap lever from the FLAPS 2 position, used for takeoff, to the intermediate FLAPS 1 position. Moments later, he instructed Kharlamov to hold the speed at 180 kts, which he did.</p><p>At 14:55:17, the flaps finished retracting into the FLAPS 1 position. At that exact moment, a chime sounded in the cockpit, and the message NAV ADS DISAGREE briefly appeared on the EWD.</p><p>Up until this point, the erroneous angle of attack values from ADS 1 and 2 had not materially affected the flight because the difference between the three AOA readings was below the rejection threshold. However, because an AOA-based correction is used when computing airspeed, ADS 1 and 2 were also providing airspeed and altitude data that was slightly too low, with ADS 2 being slightly more severely affected. Meanwhile, ADS 3 was providing accurate data. But as the airspeed increased, the difference between ADS 3 and ADS 2 also increased until the discrepancy reached 10 kts. However, the difference between ADS 3 and ADS 1 was still less than 10 kts, leading to an “ambiguous fault” scenario. As a result, none of the ADSs were rejected, and the crew was prompted to begin troubleshooting by the appearance of a NAV ADS DISAGREE message.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zMfPiymSXR29qHXg-zzXCw.png" /><figcaption>How the NAV ADS DISAGREE message would have appeared both during and after each disagreement was registered. (MAK)</figcaption></figure><p>Because the airplane was now maintaining the selected airspeed of 180 knots, it did not continue to accelerate, and the airspeed discrepancy remained right at the 10 kt threshold. As a result, very tiny variations in airspeed caused the difference to rise and fall randomly above and below 10 kts, repeatedly removing and then re-establishing the NAV ADS DISAGREE condition. Each time the conditions were met, the NAV ADS DISAGREE message appeared and a chime sounded, while each time the conditions stopped being met, the message changed from amber to white for five seconds, indicating the fault was no longer present, before disappearing. Each activation lasted about 1 to 4 seconds.</p><p>As this was occurring, Captain Bulavko called Domodedovo Radar control and secured authorization to turn left to heading 260 and climb to 10,000 feet, provided that approval from the Tretyakovo tower was also acquired. This conversation lasted 34 seconds, during which the NAV ADS DISAGREE message appeared 12 separate times.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xw-16_FvZBI7z8n7BjvVBw.png" /><figcaption>Annotated flight path, part 3: Initial flap retraction to NAV ADS DISAGREE. (MAK)</figcaption></figure><p>As Bulavko signed off with Domodedovo, Kharlamov said, “So, heading 260 set.”</p><p>“Check,” Bulavko replied.</p><p>“Vertical speed one thousand,” Kharlamov continued, carefully ensuring that all flight parameters were correct.</p><p>“Check,” said Bulavko.</p><p>“Ah, speed 180,” said Kharlamov.</p><p>But instead of replying with “check,” Bulavko’s attention was suddenly drawn to the intermittent NAV ADS DISAGREE message. “NAV ADS disagree, what the hell is that?” he asked.</p><p>The Quick Reference Handbook (QRH) procedure for a NAV ADS DISAGREE condition calls for the crew to cross-check airspeed and altitude on both pilots’ primary flight displays (PFDs) and the standby display, which receive data from ADS 1, 2, and 3 respectively, in order to identify which indication is faulty. If the faulty ADS can be identified, the procedure is simply to turn it off and select a new data source for the affected instruments. But if it can’t be identified, then the pilots are directed to complete the “Unreliable Airspeed” procedure. Notably, the NAV ADS DISAGREE procedure does not call for the crew to check the angle of attack indications.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Pmmg_5BYI9r6kxcqUgIjww.png" /><figcaption>The QRH procedure for a NAV ADS DISAGREE message. (MAK)</figcaption></figure><p>The unreliable airspeed procedure calls for the crew to first turn off the autopilot and autothrottle, then stabilize the flight path by setting a particular pitch attitude and engine thrust. During the intermediate climb phase, these values are 10 degrees pitch and Climb thrust. After stabilizing, they should level off and begin troubleshooting. The pilots are expected to execute the procedure from memory up to this point.</p><p>After leveling off, the procedure calls for the crew to reference a table of pitch, thrust, and angle of attack values (henceforth, the pitch/AOA/thrust table) in order to determine the actual airspeed. The idea is that the pilot will set a pitch, AOA, and thrust combination indicated on the chart, then cross-reference with their weight, configuration, and altitude to determine what the airspeed should be. That airspeed can then be cross-checked against the airspeed indicators to determine which one is most accurate. The procedure then provides numerous ways to troubleshoot a faulty airspeed or altitude, but it does not explain how to identify faulty AOA values or what to do if the AOA is incorrect.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4fTXTAc46o8nnBM2RKJJfg.png" /><figcaption>The unreliable airspeed QRH procedure, part 1. (MAK)</figcaption></figure><p>Instead, the procedure instructs the pilots to maintain the desired “pitch/AOA,” under the assumption that in level flight the pitch angle and AOA are equal (AOA = pitch angle minus flight path angle; flight path angle = 0, therefore pitch = AOA). It then says to stabilize the speed, cross-check all speed indications, and if necessary reference the GPS or GLONASS speed and altitude as well. If an ADS is deemed reliable, the instruments should be configured to use it and any other ADSs should be turned off. But if the faulty ADS still cannot be identified, the crew should turn off all three ADSs in order to revert the flight control system to Direct Mode. The pitch/AOA/thrust tables and the radio and GPS altitudes can then be used to fly and land the aircraft with no airspeed or barometric altitude indications.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_GnpsBUAcynANuOSN0SsbA.png" /><figcaption>The unreliable airspeed QRH procedure, part 2. (MAK)</figcaption></figure><p>Although he didn’t call for the QRH procedure, First Officer Kharlamov evidently knew it already, as he began cross-checking the airspeed indications. “Disagree… eh, mine is 180. You have how much? 180… some caution is going on and off.”</p><p>“Hundred ninet…” Bulavko started to read off the standby display.</p><p>“190, 180,” Kharlamov said.</p><p>The indications were only 10 knots apart, exactly equal to the maximum allowable divergence, and the odd one out was the standby indicator. Furthermore, the intermittent nature of the NAV ADS DISAGREE message was not envisioned by the QRH procedure and would have struck them as odd. The MAK determined that at this point the flight crew most likely felt that the warning itself was erroneous, just like the open door indication they received just two minutes earlier. Therefore, they elected not to perform the unreliable airspeed procedure — at least, not yet.</p><p>Instead, with the airplane now level at 5,000 feet, Captain Bulavko proceeded to coordinate the climb to 10,000 feet on heading 260 with the Tretyakovo air traffic manager as they had planned. During this conversation, the NAV ADS DISAGREE message disappeared from the display, seemingly confirming the decision not to continue the procedure.</p><p>“89049, at 5,000 in your area of responsibility,” Bulavko reported. “We agreed to heading 260, further climb to 10,000 feet.”</p><p>“Roger, Moscow takes over, right?” Tretyakovo asked.</p><p>“No, Moscow takes over with your permission, if we start the climb in your sector and Moscow will take us,” said Bulavko.</p><p>“I have no objection, have a good flight and a smooth landing,” Tretyakovo replied. “Gazprom 9608, QNH pressure 1019.”</p><p>First Officer Kharlamov jumped on the radio to say, “Roger, all the best, goodbye,” while Bulavko simultaneously signed off with, “1019, Gazpromavia 9608.”</p><p>In the cockpit, Bulavko told off his first officer. “Don’t talk to them, you’re always doing that,” he said. As the pilot flying, it was not Kharlamov’s job to talk to air traffic control.</p><p>Bulavko then called Domodedovo and said, “Domodedovo, Gazprom 9608, the tower doesn’t object. On heading 260, continuing to… further climb 10,000.”</p><p>“Ah, why? Ah well, there — ” Kharlamov started to say, in response to Bulavko’s admonishment.</p><p>“Vlad, fly the plane,” Bulavko ordered.</p><p>“Got it,” said Kharlamov.</p><p>“Gazprom 9608, roger, on current heading with agreement from the tower, climb to 10,000 feet, QNH pressure 1019,” said Domodedovo.</p><p>“Climbing 10,000 feet, QNH pressure 1019, Gazprom 9608,” Bulavko acknowledged. To Kharlamov, he said, “Increase speed,” and Kharlamov set the selected airspeed to 230 knots. In response, the autothrottle increased engine thrust, and the airplane began to accelerate.</p><p>“Gazprom 9608, and tell me if you’re ready to immediately follow on to Vnukovo? And what altitude will you need?” Domodedovo asked.</p><p>“Yes, we’re ready for Vnukovo immediately, but we don’t have any need for higher than 10,” Bulavko explained.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IoadWncq7HSA99xrZF6TBQ.png" /><figcaption>Annotated flight path, part 4: NAV ADS DISAGREE to clearance to 10,000 feet. (MAK)</figcaption></figure><p>During this conversation, the NAV ADS DISAGREE message appeared another eight times, ending at 14:57:12. After that, the message was never triggered again.</p><p>With everything apparently normal, Captain Bulavko set the flap handle to the flaps 0 position (fully retracted) and instructed the first officer to climb. Kharlamov then used the flight control panel to select an altitude of 9,000 feet and selected Climb mode in the autopilot’s vertical channel. He then reset the selected airspeed to 253 knots.</p><p>No one could possibly have predicted that in just 100 seconds, nothing of flight 9608 would remain but a smoking crater in a forest. What follows is a moment-by-moment account of those 100 seconds of confusion and terror.</p><p>◊◊◊</p><h3><strong>Part 4: Cascade</strong></h3><p>Up until approximately time 14:57:30, the erroneously high angle of attack values had had almost no material impact on the flight, other than skewing the airspeed and altitude slightly downward. The error of +4–5 degrees in ADS 1 and +5–7 in ADS 2 was insufficient to raise the consolidated AOA above the threshold of alpha prot, and the difference between the three AOA indications also did not exceed the threshold for rejecting any air data systems.</p><p>However, as you hopefully recall, the maximum permissible difference between the three AOA values decreases as airspeed increases.</p><p>When the pilots selected an airspeed of 230 knots, the autothrottle increased engine thrust to begin accelerating. During this time, the three angle of attack values were 9.05˚ in ADS 1, 10.46˚ in ADS 2, and 3.8˚ in ADS 3. At 206 knots, the maximum permissible AOA discrepancy is 5.22˚, decreasing to 5.11˚ at 211 knots. Therefore, somewhere between these two speeds, the threshold value decreased below the actual difference between ADS 3 and the median value, which was ADS 1. The system therefore rejected ADS 3 — <em>the only air data system that was providing accurate information.</em></p><p>With ADS 3 rejected, it was dropped from the consolidated AOA, which became the average of ADS 1 and 2. Since the AOA from ADS 3 was much lower than ADS 1 and 2, this resulted in a sudden, massive increase in the consolidated AOA value being provided to the fly-by-wire system.</p><p>At the same time, the values of alpha prot and alpha limit were decreasing due to the retraction of the flaps. Between approximately 14:57:31 and 14:57:48, the value of alpha limit decreased from 13.8 degrees to about 9 degrees, and the other threshold AOAs — alpha floor, alpha prot, alpha linear — decreased proportionally. As this decrease was beginning, the consolidated AOA jumped to a value between 9 and 10 degrees due to the rejection of ADS 3, causing the AOA to instantly surpass alpha prot. In theory, and according to the manual, exceedance of alpha prot should disconnect the autopilot, but this actually occurs at a slightly higher value that coincidentally was not reached at that moment.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6oUBEeCAubzMSclSI-wrbw.png" /><figcaption>The AOA values from each ADS, the consolidated AOA, and the AOA limiting system thresholds during the final three minutes of the flight. (MAK)</figcaption></figure><p>As soon as the AOA exceeded alpha prot, the angle of attack limiting function kicked in to prevent the AOA from reaching alpha limit. Since the value of alpha limit was actively decreasing as the flaps retracted, the limiting function began to apply angle of attack feedback to the elevator command signal in order to reduce the AOA and keep it below the rapidly shrinking alpha limit, causing the elevators to deflect in the nose down direction. As it is designed to do, the stabilizer followed this deflection, automatically moving from 3.2˚ nose up to 0˚.</p><p>As this was occurring, First Officer Kharlamov engaged Climb mode with a selected altitude of 9,000 feet, which should cause the airplane to pitch up and climb. But the autopilot was unable to deflect the elevators nose up because the AOA was already above alpha prot; the autopilot lacks the authority to increase it further. As a result, the autopilot entered Climb mode, and the autothrottle switched to thrust hold mode in the “max climb” (MCL) regime, but the aircraft didn’t climb — instead, it pitched over and began to descend while accelerating rapidly.</p><p>This autopilot behavior took the pilots completely by surprise. There had been no prior sign of trouble with the autopilot, and now suddenly it was doing the opposite of what they had commanded. There is no procedure in the QRH for this situation, nor would the pilots have encountered anything like it in training. They were in uncharted territory.</p><p>As the plane started to descend from 5,000 feet, First Officer Kharlamov’s first instinct was that he had selected the wrong mode, so he read off the flight control panel: “Wait, something, thrust, climb… Where is it going? Look!”</p><p>Since the autopilot appeared to be malfunctioning, he grabbed his side stick and pulled it fully aft in an attempt to counter the sudden descent. The aircraft correctly interpreted that he wanted to take control, and the autopilot automatically disconnected, accompanied by a loud alarm. Recognizing that Kharlamov was having difficulty flying the plane, Captain Bulavko immediately called out, “I have control” and pressed his sidestick priority button to transfer control to himself. He then deflected his side stick fully aft as well.</p><p>“You have control,” Kharlamov acknowledged, letting go of his side stick. “Look, our altitude is going somewhere,” he added. “Four… 4,500…”</p><p>As their airspeed rapidly increased, Captain Bulavko pulled the thrust levers back to idle to stop the acceleration, causing the autothrottle to disconnect. By this point the indicated airspeed was 280 knots, well above the selected value of 253 knots.</p><p>In response to Bulavko’s full nose up inputs, the elevators deflected slightly nose up, overcoming alpha prot and bringing the plane out of the descent. Since the pilot is allowed to increase the AOA up to a value near alpha limit using the side stick, the consolidated angle of attack was able to increase above alpha prot (about 7 degrees), but did not reach alpha floor (about 8 degrees). The actual AOA, calculated after the fact by the MAK, was never significantly above 3 degrees after this point. Nevertheless, this was sufficient to level the airplane.</p><p>At 14:58:00, eight seconds after taking control, Bulavko concluded that the airspeed must be unreliable and that this was somehow affecting the autopilot, so he called out, “Airspeed unreliable, Vlad.”</p><p>“Unreliable airspeed,” Kharlamov repeated.</p><p>“Tell [him] unreliable airspeed,” Bulavko instructed.</p><p>Kharlamov attempted to report unreliable airspeed to the Domodedovo controller, but amid the high stress of the situation, he forgot to switch radios, and he broadcast his call to Tretyakovo instead. In the background, Domodedovo called them repeatedly, receiving no answer.</p><p>At this time, Bulavko was performing the unreliable airspeed memory items. He had ensured that the autopilot and autothrottle were disconnected, he had gained control of the flight path, and now he increased thrust to the Climb regime while attempting to set 10 degrees of pitch. So far he was doing everything by the book, except that with his seemingly reasonable side stick inputs, he wasn’t able to achieve 10 degrees pitch. In fact, he could barely get the nose to come above the horizon. The unreliable airspeed procedure didn’t provide any guidance for the crew to follow if these actions failed to stabilize the flight path.</p><p>Unreliable airspeed was not in fact the problem, but given the previous airspeed discrepancy and the NAV ADS DISAGREE messages, it was a relatively reasonable assumption. His assumption was further supported by the sudden appearance of a NAV ADS 3 FAULT message on the EWD, triggered by the rejection of ADS 3. The pilots didn’t attempt to perform the procedure associated with this message, but it would have been a waste of time anyway — the procedure was just to turn the faulty ADS off.</p><p>“Look at the vert…” Kharlamov started to say. “Look! Ah, look, we have…”</p><p>“Need to increase the angle of attack,” Bulavko astutely observed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*JxrF2qQTeMwmgdYGjNMo-A.png" /><figcaption>Annotated flight path, part 5: The last 100 seconds. (MAK)</figcaption></figure><p>This finally prompted Kharlamov to glance at the tiny angle of attack indicator on his display. This instrument isn’t normally used except in situations like this one, so it’s unsurprising that nobody thought to check it until now. But when he did check it, he realized to his surprise that it was showing a high AOA. “Look, look what the angle of attack is!” he exclaimed.</p><p>According to the Unreliable Airspeed QRH procedure, the pilot should increase thrust and maintain altitude if the AOA is higher than commanded. Captain Bulavko faithfully acted upon this recommendation, increasing thrust even further.</p><p>At this point, armchair pilots might start pointing out that with the pitch close to the horizon and the airplane in level flight, a high AOA is impossible, and that Bulavko should have recognized this. However, I think prior events and the procedures themselves had biased him to assume that it was the airspeed that was unreliable. Nothing in his training had led him to believe that an unreliable AOA from more than one ADS at the same time was even possible, nor did the procedures available to him account for such a possibility. As such, in a highly stressful situation, it makes sense that his first instinct was to attempt to apply the procedure he knew. This also explains why he didn’t attempt to use his full side stick authority to achieve 10 degrees pitch.</p><p>Of course, increasing engine power above Climb in a nearly empty aircraft in horizontal flight will cause the airspeed to run away very rapidly. Indeed, within seconds of his thrust increase, the airspeed accelerated through 300 knots and reached VMO, triggering the SSJ-100’s high airspeed protection. At 14:58:22, the speed brakes started deploying automatically, and a robotic voice began calling out, “OVERSPEED!”</p><p>Captain Bulavko immediately responded by decreasing thrust, stopping the acceleration. The airspeed fell back below VMO, the speed brakes retracted, and the aircraft entered a very shallow climb, thanks to Bulavko’s sustained nose up inputs.</p><p>Still trying to figure out what was going on, First Officer Kharlamov again called out, “Look, we have a high angle of attack.”</p><p>Bulavko again responded by increasing engine thrust, in accordance with the unreliable airspeed procedure. At the same time, he racked his brain for some kind of answer. “Mayb — [unintelligible], because the mode is correct, so…”</p><p>“So, uh, look, this is…” Kharlamov started to say.</p><p>Suddenly, the answer hit Bulavko like a ton of bricks. “Is the angle of attack sensor not working or something?” he asked.</p><p>“Yeah and generally not [unintelligible]…” said Kharlamov.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*GnRoBHimTMe745cBVtZZ6A.png" /><figcaption>Flight data for the last 136 seconds of the flight. These data are really helpful in understanding the last part of the flight if you take the time to sit down and really understand them all. (MAK)</figcaption></figure><p>At that exact moment, the airspeed again exceeded VMO due to Bulavko’s thrust increase, triggering the high speed protections again. The OVERSPEED callout started blaring and the speed brakes began to extend. However, the airplane did not slow down, causing the high speed protection to command more and more speed brake deflection. Within seconds, the speed brakes fully deployed, massively disrupting airflow over both wings. The MAK would later calculate that the lift produced by the wings was reduced by 67 to 68%.</p><p>Predictably, this massive loss of lift caused the plane to enter a descent. Captain Bulavko immediately responded by deflecting his side stick fully aft again, but the airplane did not respond.</p><p>The reasons for this were two-fold. The first is that the speed brakes produce a nose up moment as they extend, which the high speed protection counters by adding a pitch reduction component to the elevator command signal. This partially countermanded Bulavko’s pitch up input, but it was a transient factor.</p><p>The second reason was more insidious. The fact is that the flight path angle was now decreasing — and since angle of attack equals pitch angle minus flight path angle, the angle of attack necessarily increased, even though the pitch angle didn’t change. At the same time, the value of alpha limit was decreasing from 9 degrees to about 8.5 due to the plane’s increasing Mach number. Furthermore, as I mentioned in Part 3, the SSJ-100’s angle of attack protection function doesn’t always let the AOA actually reach alpha limit, with the exact margin depending on certain unspecified dynamic conditions. The result of all these factors was that the erroneous AOA increased to a value of 7 to 7.4 degrees, then stopped dead. Not only did the angle of attack limiting function block the AOA from reaching alpha limit, it didn’t even let it reach alpha floor. However, even if the AOA had reached alpha limit, this wouldn’t have been sufficient to stop the descent.</p><p>With the erroneous AOA already pinned at the max allowable value, Captain Bulavko’s full nose up input on the side stick was blocked by the AOA limiting function and had no effect whatsoever. The plane just kept pitching farther and farther forward, chasing its own flight path in a deadly, unstoppable feedback loop.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Z7CmTSn2-Bkj0Ak5D3-A1g.png" /><figcaption>This flight data excerpt really helpfully illustrates how the pitch angle followed the flight path angle with a near constant AOA. (MAK)</figcaption></figure><p>As flight 9608 accelerated toward the ground, Captain Bulavko yanked the thrust levers back to idle, but this had no effect, so he pushed them forward to TOGA. The overspeed warning sounded continuously, and the airspeed kept increasing far beyond VMO. Within seconds he returned the thrust levers to idle, but his panicked efforts were useless. Descending through 3,400 feet, the ground proximity warning system began to blare: “TERRAIN AHEAD! TERRAIN AHEAD! PULL UP! AVOID TERRAIN! WHOOP WHOOP, PULL UP!”</p><p>“Pull up! Pull up, pull up!” Kharlamov shouted.</p><p>“Pull up, Vlad!” Bulavko yelled. “What the hell is this!?”</p><p>Kharlamov frantically pulled his own side stick fully nose up, but this had no effect.</p><p>Trapped aboard a plane that had turned into a killing machine, the pilots saw the face of death rising before them. Death was not a hooded figure with a scythe, but a patchwork of fields and forests. Death was in the leaves and the branches and the meadows, and her hand was reaching out, pushing the plane inexorably downward, crushing their desperate attempts to pull away. It is difficult to comprehend the terror one must feel, to see the ground approaching, to pull up with all one’s might, only to receive no response from the airplane, as if locked in a bad dream. But it wasn’t a dream.</p><p>At 14:59 and 16 seconds, Gazpromavia flight 9608 slammed into a forest just west of the village of Apraksino, traveling at a speed of 365 knots, pitched 25 degrees nose down and banked 25 degrees to the right. The plane clipped the tops of several trees, sliced downward through the foliage, and plowed into the ground with tremendous force. Tiny pieces of what had seconds earlier been an SSJ-100 exploded outward, tumbling through the burning woods, consumed in flame.</p><p>All three occupants were killed instantly on impact.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WCNQVuTPEZRxHH_KGcGlMg.png" /><figcaption>The crash site of Gazpromavia flight 9608. (MAK)</figcaption></figure><p>◊◊◊</p><h3><strong>Part 5: After the Fall</strong></h3><p>Over the course of its year-long investigation, the MAK reconstructed the real AOA, airspeed, and altitude throughout the flight; tested numerous AOA sensor overlay installation scenarios; interviewed dozens of people; developed a mathematical model of the flight; carried out simulated flights on a UAC test bed; studied the responses of real pilots; and much more besides. They concluded that the probable cause of the accident was the violation of the maintenance manual procedures for installing the AOA sensors, leading to similar erroneous AOA values from two out of three air data systems, which in turn led to the simultaneous activation of the AOA limiting function and the high airspeed protection function, a scenario that was never intended to occur in flight. The actions of the flight crew were found to be reasonable; they flew by the book, followed procedures, and communicated clearly with one another.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/640/0*ZM4JSZJGiaLqOv1X" /><figcaption>Recovered pieces of RA-89049, laid out in a hangar. (MAK)</figcaption></figure><p>Investigators recovered a portion of the right AOA sensor overlay still attached to a piece of the left side of the fuselage, with the marks on the overlay and fuselage still aligned, proving not only that the overlays had been swapped, but also confirming the technicians’ insistence that they had aligned the markings.</p><p>The MAK noted that the accident could have been prevented if the MOC had properly documented and labeled the overlays to ensure they were reinstalled in the correct locations, and if they had ordered inspections after the work was complete. Numerous discrepancies were identified in the facility’s record-keeping and operations, suggesting that standards were slipping.</p><p>The MAK largely avoided criticizing the design of the overlays, except insofar as drily pointing out the possibility of incorrect installation constitutes criticism. The investigation did also recommend that all operators implement a service bulletin, published by UAC after the accident, that outlines changes to the overlay design to preclude incorrect installation. However, I’m still left asking: how hard could it have been to design the overlays such that they wouldn’t fit anywhere other than the intended installation location? I think that at some point during the design process, a failure of imagination occurred, but we might never know where or why.</p><p>As for whether the flight crew could have prevented the accident, the answer was “yes, but actually no.” In general, it was found that the plane would remain controllable as long as the airspeed did not exceed VMO and the high speed protection function was not activated. However, that was easier said than done.</p><p>Tests conducted using the mathematical model of the flight, as well as test flights by trained test pilots and instructors on UAC’s test bed, revealed the following:</p><p>· If, at the moment Captain Bulavko said “airspeed unreliable” at 14:58:00, the crew had applied the unreliable airspeed memory items for this phase of flight, which were to establish a pitch of 10˚ with the thrust levers in the Climb regime, then the aircraft would have entered a climb without exceeding VMO. A pitch of 10˚ was achievable via full aft side stick deflection for 8 seconds, although this was way more than would normally be needed, and in the actual event Bulavko never achieved this. This scenario requires the pilots not to follow the recommendation to increase thrust if the AOA is too high.</p><p>· If, at 14:58:00, the crew had attempted to stabilize the flight path using the pitch/AOA/thrust table in the QRH, which at their configuration, weight, and altitude, called for 63% thrust and side stick inputs as required to stabilize the altitude, then the aircraft would have remained in level flight or a slight climb without exceeding VMO. This scenario also requires the pilots not to follow the recommendation to increase thrust if the AOA is too high.</p><p>· If, from time 14:58:02, the pilots had left the engine thrust alone and made the same pitch inputs as in reality, resulting in the thrust levers remaining at low power, the aircraft would have entered a climb and would not have exceeded VMO. The alpha floor would eventually activate to increase thrust. However, this scenario is purely demonstrative and doesn’t represent an action that the pilots would be likely to take.</p><p>· If, from time 14:58:22, when the overspeed warning sounded, both thrust levers were reduced to idle with control inputs as required to avoid exceeding VMO, the aircraft would eventually maintain straight and level flight very close to but not above VMO. This scenario again requires the pilots not to follow the recommendation to increase thrust if the AOA is too high. It also assumes that the pilots view the airspeed as reliable.</p><p>· If, after the autopilot failed to climb, the pilots had switched to Direct Mode by turning off all ADSs, the aircraft would have remained controllable and horizontal flight could have been maintained. However, no procedure called for them to switch to Direct Mode so early.</p><p>· If, after achieving flaps 0, the pilots had controlled thrust so as to avoid exceeding VMO in horizontal flight, it was possible to maintain level flight only with continuous aft side stick deflection.</p><p>· After the autopilot disconnected, while Bulavko was holding the side stick fully aft, if he had instructed Kharlamov to switch the flight control system to Direct Mode, the aircraft would have pitched up with a load factor of 6 G’s, resulting in structural failure. This is because in Direct mode the side stick is directly tied to the control surfaces without force feedback and there is no high load factor protection. If the pilots had wanted to switch to Direct Mode at any point during the final 80 seconds of the flight, they would have had to relax the side stick while making the switch, allowing the plane to enter a dive, before recovering in Direct Mode.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YWR-tvaFdh-Aim1CwcuzZA.png" /><figcaption>Distribution of debris following the accident. (MAK)</figcaption></figure><p>All of these were possible outcomes; most were good, some were better than others, one was catastrophic. But the problem with these outcomes is that they were flown by experienced test pilots and instructors with prior knowledge of the accident scenario. The question of what a real flight crew would do is answered, I think, by Bulavko and Kharlamov themselves. Throughout the flight, their actions were based on their training and the contents of the unreliable airspeed procedure, which their training and the QRH had biased them to believe was appropriate. Test pilots who flew the scenario agreed that most flight crews would interpret the abnormal situation as an unreliable airspeed event and would take actions based on that assumption. They felt that many crews would eventually increase engine power, leading to an exceedance of VMO, activation of the high speed protection, and an unrecoverable descent.</p><p>Just to prove a point, the MAK conducted tests on a flight simulator using regular airline pilots from SSJ-100 operators across Russia. The simulator wasn’t capable of simulating the failure of two AOA sensors, so the MAK set up a failure of two airspeed sensors instead, then measured how long it took for the pilots to complete the unreliable airspeed procedure and switch to Direct Mode. They found that on average, this took more than 7 minutes from the time the pilots first identified the unreliable airspeed issue. The entire flight of RA-89049, from takeoff to impact, lasted less than 6 minutes.</p><p>On flight 9608, the pilots didn’t have an opportunity to properly troubleshoot because they were unable to stabilize the flight path. During the brief flight, they experienced 22 intermittent NAV ADS DISAGREE alerts, a failure of the autopilot to respond to flight control panel inputs, a lack of normal aircraft response to side stick inputs, and AOA and airspeed values that did not match one another. These features were not covered in an any single procedure. By the time the pilots realized something was seriously wrong, they had less than a minute to identify the nature of a situation they had never previously encountered, independently develop a possible solution, and execute that solution before the situation became unrecoverable. In fact, despite the complete lack of relevant training or procedures, the pilots did identify an angle of attack sensor issue as the cause of their difficulties just 55 seconds after Kharlamov’s first call that something was amiss. Unfortunately, by then it was already too late.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/750/0*aFlZUxOmW22kroPM.jpg" /><figcaption>Officials examine the crash site. (Alexander Grechishev)</figcaption></figure><p>Flight 9608 is far from the only example of a complex systems “cascade” unfolding faster than the pilot can reasonably interpret what’s going on. The normal solution is to develop reliable indicators of the onset of the emergency and a procedure containing corrective actions. But in cases like this, that’s not really a viable answer.</p><p>During the design of the SSJ-100, and I assume every other transport aircraft ever made, the simultaneous and symmetrical failure of two AOA sensors, in such a way as to provide consistently false AOA data to the fly-by-wire system, was judged to be “extremely improbable,” with a likelihood of less than 1 in 1 billion per flight hour. As a result, UAC was not required to create a procedure for flight crews to identify or respond to such a failure. Furthermore, doing so would be impractical because small differences in the nature of the instigating event, whether it’s incorrect installation or something else, can have drastically different and unpredictable effects on the development of the situation — the “cascade.”</p><p>It is worth noting that these types of assessments don’t normally consider the possibility of maintenance errors. The probability of a mechanic swapping the overlays by accident was considerably greater than 1 in 1 billion, and the result was that the supposedly impossible happened. I covered another case of simultaneous symmetrical erroneous AOA values, also caused by a maintenance error, in my article on XL Airways Germany flight 888T; in that case, a painting crew violated the maintenance manual and sprayed an A320 with a fire hose to wash off dust, causing water to enter the AOA sensors, which then froze upon reaching cruise altitude, locking both primary AOA vanes in the neutral position. On flight 888T, the fly-by-wire system also rejected the only air data system that was providing correct information.</p><p>In any case, returning to the topic of how to handle cascading failures on a complex, modern aircraft, experts at the forefront of aviation safety are tackling that issue as we speak. There isn’t an easy catch-all solution, for the reasons I’ve already explained. One technique teaches pilots to turn off some or all automation, up to and including the flight computers and air data computers if needed, and revert to pure stick-and-rudder handling. This is sometimes effective, but not always, as illustrated by the MAK’s hypothetical scenario in which the flight crew switches to Direct Mode and instantly disintegrates the aircraft.</p><p>I think the following quotation from a 2021 Wired article by accident investigator and airline captain Shem Malmquist* illustrates the issue quite well:</p><p><em>“Hundreds of other unforeseen [automation]-related challenges could be out there that cannot be anticipated using traditional risk-analysis methods…. An effective solution needs to go beyond the limitations of aircraft designers who are unable to create the perfect fail-safe jet. As Captain Chesley Sullenberger points out, automation will never be a panacea for novel situations unanticipated in training.”</em></p><blockquote>*Note: Malmquist’s full article is useful for putting this accident in perspective; you can read it here: <a href="https://www.wired.com/preview/story/60819540c42707093e4968c1?status=draft&amp;t=1619210609701">https://www.wired.com/preview/story/60819540c42707093e4968c1?status=draft&amp;t=1619210609701</a></blockquote><p>Malmquist goes on to point out that pilots today often report knowing less about how their aircraft work than they did in the past. This restricts pilots’ ability to think of possible reasons for abnormal system behavior and develop possible solutions for scenarios that are not described in any checklist. In Malmquist’s opinion, the best way to reduce the occurrence of these types of accidents is to ensure that pilots have deeper and broader knowledge of the automated systems that control modern aircraft — not just what is traditionally considered “automation,” such as autopilots and autothrottles, but also the systems that work in the background, like the air data consolidation logic and elevator command signal components. All the crew of flight 9608 needed was the ability to recognize an angle of attack sensor problem 20 seconds earlier, and they might have successfully emerged from the crucible of the cascade.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/800/0*RFokM87m6vGkjdNQ.jpg" /><figcaption>An engine burns at the crash site. (Aviationbrk)</figcaption></figure><p>Ultimately, the crash of Gazpromavia flight 9608 was a complex accident caused by multiple interlocking issues. Changing the design of the SSJ-100’s AOA sensor overlay was a helpful and necessary step, one that would have prevented this particular accident, but the story is about much more than just the design of the airplane. It’s a case study that highlights the need to rethink some of the current assumptions about how pilots are trained to interact with automated systems. After all, the only failures were two faulty data points; other than that, all aircraft systems operated as designed, and the flight crew followed the procedures they had been trained to follow, but the airplane still crashed because there was a mismatch between the scope of the available procedures and the true range of possible problems. As I’ve already emphasized, there is no purely procedural solution to this issue. How the aviation industry will continue to adapt to the risks posed by the ever-increasing complexity of highly automated aircraft remains to be seen.</p><p>From a completely unrelated perspective, the accident also highlights how sanctions have increased the background level of risk across Russia’s aviation industry. Sanctions did not cause this accident, but they increased the probability of a maintenance error by making it impossible to follow the practices that would normally have been used to ensure that AOA sensor overlays were always reinstalled in the same location they were taken from. The bucket brigade approach used by the MOC and Gazpromavia required the maintenance team to take additional risk mitigation actions, such as labeling the overlays after removing them from the aircraft. But the technicians didn’t appreciate the potential consequences of their managers’ “solution” to the spare parts shortage, and these precautions were not taken.</p><p>This accident scenario also includes unique aspects that might be new to some pilots. One of several reasons I spent a month and a half translating the accident report and writing this article was to increase awareness of what happened that day over Russia, not because I think the exact same thing will happen again, but because studying it is thought-provoking and potentially useful. I know there are some pilots reading this, and I would be more than honored if they asked themselves — what would I do in this situation, knowing only what Bulavko and Kharlamov did? My airline pilot friends ask themselves these sorts of questions all the time, and I think this one holds value.</p><p>There is, I believe, a particular cohort of readers who might balk at the idea that pilots should have to think about this at all, simply because the supposed root cause was UAC’s failure to design an AOA sensor installation that adequately complied with the spirit of the applicable regulations. However, as Malmquist points out, the probabilistic risk analyses that manufacturers use to estimate the safety factor on each aircraft system are not even close to 100% effective at capturing all possible failure scenarios; not only because the analysis methods are designed by humans who make errors, but because the existing methods cannot always capture the “cascade.” And that’s before we even consider the fact that for a well-traveled aircraft type, the probability that a 1 in 1 billion event will eventually occur is fairly high — take, for instance, the A320 fleet, whose 330 million-plus total flight hours mean that the probability of a given 1 in 1 billion-per-flight-hour event having already occurred somewhere on the fleet is theoretically about 1 in 3.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ZU6Kczfw50dyvDmoVaaj8g.png" /><figcaption>The mangled flight data recorder from flight 9608. (MAK)</figcaption></figure><p>The point is that these events do occasionally happen, and will continue to happen, even as some manufacturers prove more scrupulous than others. And for pilots who must fly modern airplanes day in and day out, there’s understandable interest in learning about these events in order to brainstorm new techniques and strategies, if only out of a sense of professional obligation, or even self-preservation.</p><p>I’m not a pilot, just a very obsessive storyteller who knows a lot of pilots, so in the end what they do with this story is up to them. As for everyone else, I hope you found this story as fascinating as I did. Gazpromavia flight 9608 was not an accident that was widely covered in global media, no passengers were hurt, and it involved an aircraft type built and operated by Russian companies to carry primarily Russians. But the cascade transcends such boundaries. It is an outgrowth of all complex systems, visible only once it has been carefully organized into a series of second-by-second time stamps, revealing the processes that plunged the crew into unimaginable terror and confusion. No two such events are ever exactly the same, and not all of them will try as hard to kill the occupants as this one did — but some of them will, and those are the stories that stay with us long after the flames are extinguished.</p><p>_______________________________________________________________</p><p><em>Dear readers — I couldn’t have written this story and translated this report without your </em><a href="https://www.patreon.com/Admiral_Cloudberg"><em>support on Patreon.</em></a><em> Everything I produce is given to the world for free, and all of you help keep it that way.</em></p><p><a href="https://drive.google.com/file/d/1HsWVb2nSlt2saL06K4VXDqDjzUMQC17t/view?usp=sharing"><em>By the way, here’s another link to my translation of the final report, in case you don’t want to scroll all the way back up.</em></a><em> Cheers.</em></p><p><em>— Kyra</em></p><p>_______________________________________________________________</p><p><em>Don’t forget to listen to Controlled Pod Into Terrain, my podcast (with slides!), where I discuss aerospace disasters with my cohosts Ariadne and J! </em><a href="https://www.youtube.com/@ControlledPodIntoTerrain"><em>Check out our channel here</em></a><em>, and listen to </em><a href="https://www.youtube.com/watch?v=-i3dZNFDk84"><em>our latest episode about a titanic battle between a BAC 1–11 and some wind.</em></a><em> Alternatively, download audio-only versions via </em><a href="https://rss.com/podcasts/cpit/"><em>RSS.com</em></a><em>, or look us up on Spotify!</em></p><p><em>You can also see my work on Petter Hornfeldt’s YouTube channel “Mentour Pilot,” where I’m employed as a script writer and researcher.</em></p><p>_______________________________________________________________</p><p><a href="https://www.reddit.com/r/AdmiralCloudberg/comments/1ngfrgl/crucible_of_the_cascade_the_crash_of_gazpromavia/">Join the discussion of this article on Reddit</a></p><p><a href="https://www.patreon.com/Admiral_Cloudberg">Support me on Patreon</a> (Note: I do not earn money from views on Medium!)</p><p><a href="https://bsky.app/profile/kyracloudy.bsky.social">Follow me on Bluesky</a></p><p>Visit <a href="https://www.reddit.com/r/AdmiralCloudberg/">r/admiralcloudberg</a> to read and discuss over 260 similar articles</p><p><a href="https://docs.google.com/document/d/18nXtJumuRkhZCJffC0FFAilgDGIiImU2y_5hvYL79aw/edit?usp=sharing"><strong>Bibliography</strong></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=50e225baece3" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[How Not to Run an Airline: The 2024 Saurya Airlines CRJ-200 crash]]></title>
            <link>https://admiralcloudberg.medium.com/how-not-to-run-an-airline-the-2024-saurya-airlines-crj-200-crash-3ecd538222d3?source=rss-e119a26506e3------2</link>
            <guid isPermaLink="false">https://medium.com/p/3ecd538222d3</guid>
            <category><![CDATA[aviation]]></category>
            <category><![CDATA[asia]]></category>
            <category><![CDATA[nepal]]></category>
            <category><![CDATA[flying]]></category>
            <category><![CDATA[technology]]></category>
            <dc:creator><![CDATA[Admiral Cloudberg]]></dc:creator>
            <pubDate>Fri, 01 Aug 2025 20:30:16 GMT</pubDate>
            <atom:updated>2026-01-16T04:11:07.355Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*cBoQ8bYOUu0g6xQ5.png" /><figcaption>Stills from a cell phone video show Saurya Airlines’ CRJ-200 immediately before and after the crash. (AP)</figcaption></figure><p>On the 24th of July 2024, a regional jet plunged to the ground and exploded seconds after takeoff from Kathmandu, Nepal, killing 18 people and leaving the captain as the sole survivor. The accident devastated the tiny airline, which not only lost one of just two operational aircraft, but also nearly half its managerial staff, five of whom were on the plane. But none of them should have been there, because this wasn’t a passenger flight — in fact, it was a ferry flight intended to relocate the aircraft, which had not flown in 34 days, to the city of Pokhara for maintenance. Carrying passengers on a ferry flight is unambiguously illegal. But that was just the tip of an iceberg of negligence — including several outlandish regulatory violations — that has been only partially revealed by the release of the investigation commission’s final report, one year after the crash.</p><p>Following the 2023 crash of Yeti Airlines flight 691, I wrote an article analyzing that accident in the broader context of Nepal’s poor safety record, which has made it one of the most dangerous places to fly. Now, the Saurya Airlines crash in Kathmandu has again highlighted the same issues that come up over and over in Nepalese accidents, and I don’t just mean the harsh terrain and bad weather — because this accident had nothing to do with environmental factors, and much more to do with the airline’s complete disregard for safety at every level. But it’s very difficult to determine the root cause of that disregard, in large part because Nepal lacks an independent accident investigation agency willing to pursue every lead. The following story of brazen negligence, incompetent operation, and glaring investigative omissions perfectly illustrates why that needs to change.</p><p>◊◊◊</p><blockquote>Note: If you haven’t already, I recommend reading <a href="https://admiralcloudberg.medium.com/levers-of-power-the-crash-of-yeti-airlines-flight-691-caedd8f8f7e0">my aforementioned article on Yeti Airlines flight 691</a>, either before or after reading this one. This article is partially written as a follow-up to that article. This article can be read as a standalone piece, but the previous article does provide helpful context.</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*62DeDnZQOcfMGpRGcUzDjw.png" /><figcaption>A view over Kathmandu on a clear day. (Nepal Vision Treks)</figcaption></figure><p>Nepal is a country blessed with extraordinary beauty, from the clouds of ice crystals blowing off the glaciated summits of the world’s highest mountains, down through precipitous gorges where sky-blue rivers tumble, to the terraces and temples of the foothills and the metropolitan fervor of the capital, Kathmandu. As beautiful as it may be, traversing that terrain by air can be hazardous for locals and tourists alike. But, if we want to adapt the proverb, it may be said that flying is the riskiest form of transport in Nepal, except for all of the others.</p><p>As of 2025, Nepal consistently ranks as one of the most dangerous countries in which to board an airplane, as measured by the number of fatal accidents divided by total commercial aircraft movements. Between 2010 and 2024, there were at least 12 fatal commercial airplane accidents in Nepal, most of which involved controlled flight into terrain while maneuvering near treacherous mountain airports in poor visibility. That’s more crashes than practically any other country suffered during the same period, including many countries with orders of magnitude more aircraft movements.</p><p>While geography contributed to most of these accidents, practically all of them were blamed at least in part on inadequate oversight by the Civil Aviation Authority of Nepal, or CAAN. In fact, according to a 2023 ICAO audit, the CAAN’s ability to oversee Nepal’s growing aviation industry is getting worse, not better. The agency is critically short-staffed and its leadership is more interested in swanky infrastructure projects than the day-to-day drudgery of running a safe system. The flight standards and flight operations monitoring departments are nowhere near the staffing levels required to provide even basic surveillance of most airlines, and major safety violations almost never result in enforcement action. For this reason, all Nepalese airlines have been blacklisted by the European Aviation Safety Agency for years.</p><p>This is the story of one of those airlines.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*siczqQ18o1JFyMEm" /><figcaption>Passengers board 9N-AME, the accident aircraft, seen here in its previous livery. (Anurup Prathak)</figcaption></figure><p>In 2014, Nepal welcomed a tiny new air carrier called Saurya Airlines, which promised to become the country’s second airline to offer domestic services using jet aircraft. Cosmic Air, the first airline to try that, went bankrupt in 2008.</p><p>Saurya Airlines began operations with one Bombardier CRJ-200 twin rear engine regional jet, serving just two routes between Kathmandu and the cities of Biratnagar and Bhadrapur in the far southeastern part of the country. Although the airline’s founders had plans to grow their network, attempts to expand to five other cities ended in failure and the routes were terminated.</p><p>In 2016, a new law imposed a minimum fleet size of two aircraft for all Nepalese airlines engaged in scheduled passenger flights, presumably in order to encourage consolidation of tiny, unreliable airlines like Saurya. For a period of several months, Saurya Airlines was restricted to charter operations before it regained permission to fly scheduled flights in 2017 following the purchase of two additional CRJ-200s.</p><p>This reprieve didn’t last long. On July 7, 2018, Saurya Airlines suspended all flights due to financial difficulties, remaining grounded for over a month before resuming service on August 21. Three months later, the same thing happened again, and this time the grounding lasted even longer, from November 27, 2018 to March 7, 2019. Why the perpetually bankrupt airline was not grounded by the CAAN, or at least seized by its creditors, is unclear. In any case, it managed nine whole months of continuous operation this time, before being grounded on December 24 due to the nascent Covid-19 pandemic.* Flights did not resume until October of 2020.</p><blockquote>*Note: The final report states that this was the reason for the grounding, but Nepal didn’t record its first case of Covid-19 until January 23, 2020. I was not able to reconcile this. Most likely the airline was initially grounded for some other reason.</blockquote><p>Following the pandemic, the airline somehow emerged intact. Now operating with two aircraft — the third went into storage in 2018 and never came back — the company managed to fly back and forth between Kathmandu and the southeastern lowlands without any major interruptions for more than three years. This unbroken streak convinced Saurya Airlines executives to publicly suggest that they might purchase ATR twin turboprops to expand their network, but this never took place. Instead, the company kept flying its two airworthy CRJs as often as it could, which was at least some of the time.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/640/0*YbstvJ3tkRg1v52G" /><figcaption>9N-AME as it appeared at the time of the accident. (Saurya Airlines)</figcaption></figure><p>One of those aircraft, a 21-year-old CRJ-200 registered 9N-AME, came due for a certificate of airworthiness renewal inspection in March 2024. The inspection found the aircraft airworthy, with the caveat that an overhaul of the main landing gear would have to be completed by April 20. Saurya Airlines applied for and received an extension of that deadline to June 19, but that too expired with the work still not started. Consequently, on June 21 the aircraft was withdrawn from service and placed into short term storage until such time as the landing gear overhaul could be accomplished. The final report doesn’t say why this work took so long to get started, but given Saurya Airlines’ history, one wonders if that time might have been spent trying to scrape together enough cash to pay for it.</p><p>9N-AME ended up sitting at Kathmandu’s Tribhuvan International Airport for a total of 34 days, with short term storage checks every 7 days to keep it ready for flight. The landing gear overhaul was finally completed on July 22nd, but before the plane could return to service, it came due for a C-check — a regular heavy inspection performed approximately once every two years, or after a certain number of flight cycles. Apparently — the final report is light on details — Saurya Airlines used, rented, or contracted a C-check facility at the new Pokhara International Airport in Pokhara, Nepal’s second largest city. This airport and its sordid history should be familiar if you’ve read my Yeti Airlines article.</p><p>Following completion of the landing gear overhaul, Saurya Airlines requested and received CAAN approval to ferry the aircraft from Kathmandu to Pokhara for the C-check. Such a ferry flight is legally distinct from other flight types. Unlike a repositioning flight, in which the empty aircraft is moved to a new location for scheduling reasons, the purpose of a ferry flight is to move the aircraft for maintenance specifically. Ferry flights can be conducted with major mechanical failures on the aircraft, up to and including a failed engine (for some types). Such flights must carry only essential flight crew members, whereas there is no such restriction for repositioning flights.</p><p>It turns out that Saurya Airlines had no intention of complying with that regulation. In fact, besides the two pilots, a total of 17 other people made plans to travel on the ferry flight to Pokhara. Most of them were maintenance engineers, but the unauthorized passengers also included an off duty pilot, as well as Yagya Poudyal, Saurya Airlines’ Maintenance Manager; Ashwin Niroula, Continuing Airworthiness Manager; Dilip Verma, Chief of Quality Assurance; and Sagar Acharya, the Chief of Safety. Furthermore, even though the manifest listed all passengers as Saurya Airlines staff, two of them were not employees of the airline at all, but rather the wife and four-year-old child of one of the staff members.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/823/0*IOOUSR017MswD4DA.jpg" /><figcaption>The full list of passengers on the accident flight. (The Rising Nepal)</figcaption></figure><p>The final report on the accident doesn’t explain why all these people were traveling on the ferry flight, but since they were mostly in maintenance-related roles, I would assume that they were going to carry out the C-check, and the airline decided to place them on the ferry flight because it was cheaper than booking seats on a legitimate flight. Besides, there wasn’t anything mechanically wrong with the aircraft, so it was probably seen as a paperwork issue more than a safety issue. Still, as Chief of Safety, Acharya at least should have understood that paperwork, while a mere simulacrum of reality, does tend to reflect something constative. In fact, according to FAA statistics, ferry and repositioning flights are substantially more likely to be involved in an accident compared to scheduled flights, regardless of whether the airplane is being ferried with mechanical defects or not.</p><p>The fact that key personnel in charge of safety at Saurya Airlines saw no problem with such a blatant regulatory violation reflects as poorly on the CAAN as it does on their own judgment. Unhesitating willingness to violate rules doesn’t come from nowhere; rather, it develops when no one is held accountable for their actions. The actions of the airline’s management in this case suggest that they knew they would not be caught, or knew that if they were caught, nothing would happen.</p><p>◊◊◊</p><p>In addition to the 17 passengers, two pilots were selected for the flight. The first officer was 26-year-old Sushant Katuwal, a young airman with about 1,800 total flying hours, almost all of which were on the CRJ. He had obtained his pilot’s license in South Africa in 2019 and was hired straight out of flight school by Saurya Airlines, which sent him for CRJ ground training in Lithuania and simulator training in Germany. However, he failed his type rating simulator check, resulting in additional training that forced him to remain in Germany for an extra three months. Saurya Airlines later deducted the extra training expenses from his salary, and the company did not cover room and board, forcing him to take out a loan. He was still repaying the loan at the time of this flight, five years after the fact.</p><p>Katuwal’s finances were further strained when the airline furloughed him without pay during the Covid-19 pandemic. According to interviews with his friends, family, and colleagues, he was unhappy with the compensation and benefits that Saurya Airlines provided, and he was struggling financially. It also turned out that he had hidden the loan from his parents, which no doubt piled even more stress onto his shoulders. Considering all of these factors, there was almost no chance that Katuwal would turn down any flight assignment.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/900/0*2-YAA5LcrhSZQnwt" /><figcaption>Undated photo of Captain Manish Shakya. (Saurya Airlines)</figcaption></figure><p>The captain assigned to the ferry flight was 35-year-old Manish Shakya, who was also the airline’s Chief of Operations. He had 6,185 total hours, including almost 5,000 on the CRJ, over a 16-year career. He first obtained his pilot’s license in the Philippines in 2009, then returned to Nepal to fly the Beech 1900D for local carrier Guna Airlines. He joined Saurya Airlines shortly after its founding in 2015 and was sent to Lithuania and Germany to receive a CRJ type rating, just like First Officer Katuwal, except that he completed the training on the first try.</p><p>As the Chief of Operations, Shakya would have been aware of the decision-making behind carrying passengers on the ferry flight, and he might have even been involved in that decision-making. As a result, there was little chance that he would object to this violation either.</p><p>And so the plans for ill-advised flight went ahead, apparently without any objections from anyone.</p><p>◊◊◊</p><p>On the morning of July 24, a return to service check was completed, and airline personnel immediately began preparing 9N-AME for the flight to Pokhara. These preparations included the loading of a considerable quantity of cargo, which included but was not limited to maintenance equipment and consumables, toolboxes, wheel chocks, and food. The cargo was not loaded by the cargo handlers at Kathmandu, but rather by Saurya Airlines’ engineering staff, who possessed neither the appropriate licenses nor training to load an aircraft.</p><p>After filling the CRJ’s cargo compartments to the brim, these untrained personnel began loading additional cargo directly into the passenger cabin. The items were placed in the passenger seats with no restraint mechanism whatsoever. Even worse, this cargo included containers of flammable lubricants, cleaning solutions, hydraulic fluid, and engine oil. None of these hazardous materials were secured, nor was Saurya Airlines authorized to carry hazmat in the first place. Although the cargo loading blatantly violated three or four basic regulations, cockpit voice recorder evidence indicates that the pilots were aware of this arrangement and did not object.</p><p>The first pilot to arrive at the plane was First Officer Katuwal, sometime prior to 10:08 a.m. local time (UTC +5:45). The cockpit voice recorder was already running, and from that time it recorded Katuwal as he calculated the V-speeds for takeoff.</p><p>The V-speeds are the speeds that pilots use to time certain decisions and actions during the takeoff roll. Before every flight, the pilots calculate V1, the highest speed at which the takeoff can be rejected; VR, rotation speed; and V2, the takeoff safety speed, used in the event of an engine failure. Since these values are affected by the weight of the aircraft, the length of the runway, the temperature, the airport elevation, and other factors, the exact speed values vary from one flight to the next.</p><p>Although most major airlines use software programs to calculate the V-speeds, manual calculation was the historical norm, and still is in many places. For manual calculations, airlines provide pilots with a set of cards containing tables of figures, which are stored in the cockpit for easy reference. Pilots select the card corresponding to the projected takeoff weight and flap setting, which contains the base V-speeds, then add corrections for temperature and elevation by cross-referencing a corrections table. An example V-speed card from Saurya Airlines can be seen below.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*25dZ5F7LbMustgwSGa6SaA.png" /><figcaption>An example V-speed card from Saurya Airlines. (Nepal AAIC)</figcaption></figure><p>For this flight, the reported temperature was 26˚C with an airport elevation of 1,330 m (4,360 ft) and a planned takeoff flap setting of 20˚. The weight of the aircraft wasn’t precisely known because the passengers didn’t check in by the normal process and their baggage hadn’t been weighed. However, the dispatcher estimated that there were 600 kg of baggage on board, which in addition to the weight of the cargo, the fuel, the occupants, and the airframe resulted in a total calculated weight of 18,137 kg (39,985 lbs). Later, investigators algebraically derived the true weight of the aircraft using performance figures from the flight data recorder, which proved that the dispatcher’s estimate was fairly accurate. The real weight was assessed to have been about 18,300 kg (40,345 lbs) ±200 kg (441 lbs), a range that includes the dispatcher’s estimated weight. Since the V-speed cards were provided in 500 kg increments, and since pilots were expected to round up to the nearest 500 kg when calculating the V-speeds, any difference between the actual and calculated weights would not have changed the resulting V-speeds because the 18,500 kg card would have been used in all cases.</p><p>Using the aforementioned card, First Officer Katuwal calculated that V1 would be 114 knots; VR 118 kts; and V2 126 kts. These were the correct values for the current temperature and elevation using the 18,500 kg V-speed card. But he had no way of knowing that the card itself was wrong.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*I-d6TnJ_I65ZfgBWSGFDfw.png" /><figcaption>Observe that the base V-speeds (left column on each table) on the 17,500 kg and 18,500 kg cards are the same. (Nepal AAIC)</figcaption></figure><p>The V-speed cards were created, presumably in 2014, by Saurya Airlines using the manufacturer’s data. At that time, the person who formatted the cards apparently copy-pasted the entire V-speed table from the 17,500 kg card onto the 18,500 kg card without changing anything. The final report doesn’t explain how this mistake escaped detection during approval of the card deck, nor does it explain why pilots didn’t detect the error. However, it seems likely that the 18,500 kg card was rarely used, since 9N-AME had a maximum takeoff weight of 24,400 kg. Most passenger flights are loaded fairly close to the maximum takeoff weight, or at least closer than 18,500 kg. At the same time, flights with the aircraft completely empty would weigh much less than 18,500 kg. So with 17 passengers in the 50-seat aircraft, plus cargo, the weight would have fallen into a middle area that would have been rarely encountered during normal operations. All of that having been said, it wasn’t the pilots’ responsibility to detect the discrepancy, and it should have been caught during routine paperwork inspections. Either these inspections were not being conducted or they were conducted in a disinterested manner.</p><p>After the accident, investigators calculated that the correct V-speeds would have been V1=117 kts, VR=122 kts, and V2=127 kts. These values were quite close to those calculated by the first officer, except for VR, which was four knots higher. This might not seem like a lot, but safety is eroded in increments.</p><p>The purpose of VR is to define a point at which the aircraft will respond to nose up pitch inputs by becoming airborne in a safe manner and with a reasonable margin for error.</p><p>If rotation is initiated very early, the nose will come up but the plane will stay on the ground until it has built up enough speed. That’s because airspeed is one of the components of the lift equation. Without enough of it, the airplane will not become airborne.</p><p>The lift equation has many components, but if we assume a constant aircraft configuration, weight, air density, and so on, then the two components most directly controlled by the pilot are airspeed and angle of attack. Angle of attack, often described as the angle of the lifting surfaces into the oncoming airflow, is also approximately equal to the difference between the pitch angle and the flight path angle. The higher the angle of attack (or AOA), the greater the lift coefficient, up until to the critical point, where airflow separates from the upper wing surface, a stall occurs, and the wing ceases to generate meaningful lift.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ovcEOELUB8CaUAfkvcsQkw.png" /><figcaption>The relationship of pitch, AOA, and flight path angle during rotation and liftoff, part 1. (Own work, airplane photo by Anurup Prathak)</figcaption></figure><p>Since all parameters other than these two are assumed to be constant during an exemplar takeoff, the amount of lift required to counteract the aircraft’s weight and become airborne is also a constant. Therefore, if the airspeed is lower, the required angle of attack must be correspondingly higher to compensate. In theory, below a certain airspeed, the AOA required to become airborne may even be above the critical AOA, resulting in an immediate stall if liftoff is attempted. However, many aircraft are geometrically limited, meaning that the tail will strike the ground at a certain pitch angle, effectively limiting the AOA to a value equal to that pitch angle (since the flight path angle is zero while on the ground). These aircraft will simply continue rolling until the airspeed is high enough to initiate liftoff at the constant geometrically limited AOA. That tangent aside, the point is that even rotating as little as four knots early means that the aircraft will need to achieve a higher AOA before it lifts off, and the difference between that AOA and the critical AOA will be less than if the rotation had been initiated at the correct speed.</p><p>It’s also worth noting that an aircraft on or near the ground will be influenced by “ground effect,” which tends to increase lift for a given AOA while also reducing the critical AOA. This can make it easier to stall non-geometrically-limited aircraft during rotation, and it can also result in a failure to climb after liftoff if the takeoff is very marginal (i.e. close to the minimum possible airspeed and maximum possible angle of attack).</p><p>Another factor that greatly affects the liftoff is the rate at which the pilot rotates. If the rotation rate is very slow, it will take longer to reach the required AOA, and the airplane will consume more of the runway. On the other hand, if the rotation rate is too fast, a stall could occur.</p><p>When the pilot pulls back on the controls, that input is transmitted to the elevators, which deflect in a nose up direction. Aerodynamic forces then pivot the aircraft about its center of lift, increasing the pitch angle. This increased pitch angle results in an increased AOA, which in turn increases lift, causing the flight path angle to rise. The airplane then lifts off and climbs away. But what’s important about this sequence is that AOA responds to control inputs before the flight path angle does. Therefore, if the AOA increases very rapidly, it could reach the critical point before the flight path has time to respond.</p><p>During a normal rotation, the pilot aims to achieve a pitch angle generally around 15 degrees (for jet transport aircraft at least). Of course, applying 15 degrees pitch up instantly would result in an AOA of 15 degrees as well, which would stall the aircraft. By contrast, pitching up slowly allows the flight path to respond before the AOA gets anywhere near the critical point. Once the flight path has responded positively, a higher pitch can be achieved without stalling, since AOA equals pitch angle minus flight path angle.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*k9nMXLxXZRvryuJ8ARwkww.png" /><figcaption>The relationship of pitch, AOA, flight path angle, and rotation rate during rotation and liftoff, part 2. (Own work, airplane photo by Anurup Prathak)</figcaption></figure><p>Pilots of jet transport aircraft are usually taught to rotate at a rate of 2.5 to 3 degrees per second. Three degrees per second is the actual target, but rotating too fast is more dangerous than rotating too slowly, so the acceptable range is sometimes lowered to 2.5 to discourage over-rotating. According to Petter Hornfeldt (Mentour Pilot), with whom I discussed this case,* another common strategy to avoid over-rotation is to start rotating, then stop and gauge the response of the aircraft before continuing.</p><p>According to recorded flight data, Saurya Airlines’ CRJ-200 aircraft typically became airborne at an angle of attack between 6 and 8 degrees. The CRJ-200’s stall AOA under generic takeoff conditions, accounting for the influence of ground effect, is not stated in the final report, but the data suggests that it was about 10 degrees. That margin isn’t immense, and it’s below the CRJ’s geometric limit, which is why the flight operations manual strongly warned against rotating too quickly, due to the high stall risk.</p><p>(If anyone is wondering where the discussion of load factor is — load factor is simply another way of understanding why the flight path vector changes when the pilot raises the nose. Discussion of load factor is not necessary to explain this accident.)</p><blockquote>*Note: For those who are unaware, since summer 2024 I have been working as a researcher and script writer for Mentour Pilot on YouTube. <a href="https://www.youtube.com/@MentourPilot">Check out his channel </a>if you’re interested in seeing my work brought to life by a professional team of animators and graphic designers and edited and narrated by a professional pilot with more than 20 years of experience.</blockquote><p>◊◊◊</p><p>After First Officer Katuwal calculated the V-speeds, Captain Shakya arrived at the aircraft at around 10:40. He asked Katuwal which checks had been performed, provided some general instructions, then started conversing with passengers about the new Pokhara Airport, the C-check, and topics unrelated to the flight. Notably, he did not cross-check Katuwal’s V-speed calculations, which is required. However, since he was also unaware of the incorrect V-speed card, it was unlikely that he would have detected the error.</p><p>After the last passengers boarded at 11:02, the crew closed the doors and began starting the engines. The left engine didn’t start on the first try, but it sputtered to life on the second attempt.</p><p>In the back, the passengers settled in next to the overflowing cargo. Although a flight with 17 passengers on the CRJ-200 normally requires a flight attendant, none was provided, and no safety briefing was conducted. It is unknown whether the passengers wore seat belts.</p><p>As the pilots taxied the aircraft up to the head of runway 02, they performed the before takeoff checks, but the control checks, intended to verify that full range of control surface movement, were only partially completed. Why the pilots chose to skip some checks before taking off in an airplane that was parked out in the open for 34 days is a mystery to me, but maybe that’s because I have a sense of self-preservation.</p><p>By the time 9N-AME lined up for takeoff, so many rules and regulations had been violated that the plane might well have arrived safely at its destination by breaking the laws of physics, too. But the thing that would tip this flight over the edge of disaster wasn’t the poorly loaded cargo, or the flammable liquids in the cabin, or the skipped control checks. No, it was something a little less glamorous but no less important: a lack of flight operations quality assurance.</p><p>After the accident, investigators downloaded flight data stretching back more than a year and a half from both 9N-AME and its sister ship 9N-ANM. This data showed that while most rotations were normal, a concerning number of rotations were performed with a 1-second rotation rate* greater than 4˚/s, and 14 takeoffs had a 1-second rotation rate greater than 5˚/s.</p><blockquote>*Note: 1 second rotation rate means the average rate over the course of one second. The sampling interval for pitch was 4 times per second.</blockquote><p>The two fastest rotations occurred on January 11, 2024 and March 19. 2024, and featured 1-second rotation rates of 5.8 and 5.5˚/s, respectively. Records indicated that in the latter event, Captain Manish Shakya was flying the plane.</p><p>The final report doesn’t explain why a chronic problem with excessive rotation rates developed at Saurya Airlines. It’s common for trainee pilots to over-rotate at first, but these rookie mistakes should be drilled out by the time the trainee walks out of a flight school with a type rating. Over-rotation should also have been something that instructors look out for during recurrent training, especially since the manual explicitly warned against it. Evidently these things did not happen. As for why, I only have an untested hypothesis. It is possible, but not provable, that in the absence of appropriate correction by instructors, Saurya Airlines pilots developed an overly aggressive rotation technique because the CRJ-200 is very easy to load with an excessively forward center of gravity, which will make it harder to bring the nose up on takeoff. Because of its very aft center of lift, it’s difficult to load a CRJ-200 with the CG too far aft, but it’s very easy to do the opposite. Anecdotally, CRJ pilots often have to move passengers and bags around to keep the center of gravity within the forward limit.</p><p>If Saurya Airlines pilots became accustomed to rotating sharply to compensate for a forward CG, they might end up rotating too aggressively when the CG is farther aft, leading to an over-rotation. Furthermore, as the first Nepalese operator of the CRJ series, there might not have been a lot of institutional knowledge of these issues. But again, that’s merely my own hypothesis, not an investigative finding.</p><p>◊◊◊</p><p>At 05:25:25, First Officer Katuwal reported ready for departure, and the Tribhuvan tower controller cleared them for takeoff. With Captain Shakya at the controls, the pilots pushed the thrust levers forward and began the takeoff roll, accelerating away down Kathmandu’s 3,000-meter runway.</p><p>At 114 knots, Katuwal called out “V1,” followed by “rotate” at 118 knots. Shakya responded by initiating the rotation with a sharp nose-up input on his control column, one that would have required considerable strength. Because the aircraft was relatively light, with a reasonable center of gravity, this input was massively excessive. The resulting 1-second rotation rate peaked at 6.5˚/s, the highest ever recorded at Saurya Airlines.</p><p>Because Shakya was rotating at a lower than optimal speed, the AOA required to become airborne was higher than normal, and therefore the flight path would take longer to respond. Then, when he rotated at a rate of 6.5˚/s, the AOA rose so fast that it indeed approached the critical point before the flight path adequately responded. As a result, the stick shaker stall warning triggered just two seconds after liftoff at a height of 11 feet (3.3 m) above the runway. 9N-AME’s right wing had a chronically higher AOA due to some unidentified asymmetry, as a result of which the right side stick shaker activated one second before the left side, but this was of little importance. Either way, the only way to prevent a stall was to reduce the angle of attack.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wJ3S3panQjFQVYq6IrTKxw.png" /><figcaption>Flight data during the takeoff and brief flight of 9N-AME. (Nepal AAIC)</figcaption></figure><p>First Officer Katuwal reacted immediately to the rapid rotation and stick shaker, shouting, “Woah, woah woah, sir, sir, sir!” Unfortunately, his alarm didn’t translate into useful instructions, like “reduce pitch.” Even with rigorous upset training, few people have the clarity of mind to say anything useful in the first few seconds after such a surprising event, and these guys didn’t have that kind of time.</p><p>Pilots are trained to respond to a stick shaker on takeoff by applying maximum power and reducing the pitch to a shallow positive angle. Why that didn’t happen here is difficult to say. Perhaps the pilots had not drilled this scenario in the simulator recently, or perhaps events unfolded so rapidly that they were plunged into panicked confusion. In any case, Shakya continued to pitch up toward 15 degrees, while the angle of attack rose above 10 degrees, and the airplane began to stall. Beginning three seconds after liftoff, the right wing lost lift and dropped, sending the plane into a 25-degree right bank at very low altitude. Captain Shakya immediately threw the controls to the left to stop the roll, but he overcorrected, causing the plane to reach a dizzying 55-degree left bank before it began to roll back the other way. Throughout these few seconds, the stick shaker continued to rattle away, and the AOA hovered around 10 degrees.</p><p>Approaching 100 feet above the ground, the floor fell away beneath them, and the aircraft entered a fully developed stall. The right wing ceased to generate lift and the plane snapped over beyond the vertical, banking 94 degrees to the right. On the ground, people pointed, shouted, and ran. In the cockpit, the pilots seemed paralyzed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*l093TlupGKPS82pevWkyVw.png" /><figcaption>Stills from airport CCTV footage show the airplane banking wildly in both directions. (Nepal AAIC)</figcaption></figure><p>Because the CRJ is a T-tail aircraft, it is at risk of entering a so-called “deep stall,” in which the plume of disrupted air from the stalled wings envelops the elevators, leading to a loss of pitch control. In order to prevent this, the CRJ was required to have a “stick pusher,” which physically pushes the control columns forward to assist in the recovery before it’s too late. This device now activated, pushing the nose down below the horizon, but at such a low altitude, recovery was impossible. As the ground rose up beneath him, Captain Shakya desperately leveled the wings and pulled back with all his might, overriding the stick pusher in a panicked attempt to prevent a now inevitable crash.</p><iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FJdUtu8QAjIY%3Ffeature%3Doembed&amp;display_name=YouTube&amp;url=https%3A%2F%2Fwww.youtube.com%2Fshorts%2FJdUtu8QAjIY%3Ffeature%3Dshare&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FJdUtu8QAjIY%2Fhq2.jpg&amp;type=text%2Fhtml&amp;schema=youtube" width="640" height="480" frameborder="0" scrolling="no"><a href="https://medium.com/media/308837b531a8ce9eb0818a1c69d5b051/href">https://medium.com/media/308837b531a8ce9eb0818a1c69d5b051/href</a></iframe><p>Thirteen seconds after liftoff, the CRJ-200 crashed into the airport surface off the right side of runway 02, in a 30-degree right bank with 6 degrees of nose up pitch. The right wingtip gouged a furrow across a taxiway, then the wing exploded and the airplane cartwheeled, rolling inverted as it careened across the grass in a cloud of billowing flame. A split second later, the fuselage slammed into a shed, a helicopter, and a shipping container belonging to local helicopter company Air Dynasty. The impact sheared the cockpit away from the cabin, and the flight deck embedded itself into the shipping container. Locked together, the cockpit and the container plunged down an embankment into a ravine and came to a halt.</p><iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2Fi3huiLxl_gM%3Ffeature%3Doembed&amp;display_name=YouTube&amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3Di3huiLxl_gM&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2Fi3huiLxl_gM%2Fhqdefault.jpg&amp;type=text%2Fhtml&amp;schema=youtube" width="854" height="480" frameborder="0" scrolling="no"><a href="https://medium.com/media/f8876868787467931d09596dd69d1363/href">https://medium.com/media/f8876868787467931d09596dd69d1363/href</a></iframe><p>Meanwhile, the main fuselage and wings continued over the ravine, trailing fire and smoke, before plowing into a construction site 21 meters below the airport elevation. Powered by fuel from the ruptured tanks, the fire breached the badly damaged passenger cabin and swept through the interior, which was soaked in hydraulic fluid and oil from the improperly secured cargo. Although autopsy results suggested that blunt force trauma contributed to the deaths of all of the passengers, anyone who might have survived the initial impact certainly could not have escaped the fire, which overtook the cabin before rescuers could arrive.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*uvOQDsMcL7_eBan3.jpg" /><figcaption>The crash site after the fire was extinguished. The main portion of the airplane is in the foreground, while the cockpit and shipping container can be seen in the background. (AFP)</figcaption></figure><p>At the airport, practically everyone with a view of the runway witnessed the crash, prompting numerous ground personnel to run toward the crash site to search for survivors. The air traffic controllers also sounded the crash alarm, and fire trucks raced toward the scene, arriving in less than two minutes.</p><p>The first fire truck arrived to find that the aircraft had fallen down an embankment and was largely inaccessible. The fire crew were able to spray water onto the cockpit, which came to rest closer to the edge, but the cannons couldn’t reach far enough to suppress the huge conflagration consuming the cabin. Furthermore, the construction site was fenced off with limited gates, and the nearest gate down at the street level was blocked by construction materials, hindering access. And to make matters worse, the second fire truck to arrive at the scene did nothing to help; no foam or chemical suppressants were used; and no firefighters immediately attempted to descend the embankment to search for survivors. That task was left to untrained ground handlers, who arrived at the crushed cockpit to find Captain Manish Shakya struggling to extricate himself from the tangled wreckage. Miraculously, they managed to pull him free and assist him up the embankment to a waiting ambulance.</p><p>Unfortunately, while Shakya was rushed to the hospital with serious but non-life threatening injuries, First Officer Katuwal and an off duty pilot riding in the jump seat could not be saved before fire overran the cockpit. The final report states that impact forces for the cockpit occupants were theoretically survivable, but the two pilots who died on the flight deck suffered severe trauma prior to receiving burn injuries, and it remains unclear whether a more prompt rescue response could have saved them.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/741/0*v3LcivfpL22YkW4P.jpg" /><figcaption>The location of the crash site relative to the airport. Not so fun fact: the wreckage of the airplane can be seen on current google earth satellite imagery. (Nepal AAIC)</figcaption></figure><p>In all, 18 people were killed in the crash, including Saurya Airlines’ Chief of Quality Assurance, Chief of Safety, Continuing Airworthiness Manager, and Maintenance Manager. Captain Manish Shakya, the airline’s Chief of Operations, was the only survivor.</p><p>In their final report, investigators criticized the Tribhuvan Airport fire rescue services for their disorganized response, which the report partially blamed on a failure to include the area of the crash site in tabletop or full-scale response exercises. However, both the response and the severity of the crash itself were also negatively affected by the presence of buildings and steep terrain in the impact zone. Under International Civil Aviation Organization (ICAO) rules, runways in the same class as Tribhuvan’s runway 02 should have a clear area extending for 140 meters either side of the runway centerline, but the Air Dynasty equipment struck by the airplane was only 120 meters from the centerline, and the down-sloping embankment was even closer. In the investigators’ opinion, if the required 140-meter clear area had been established, the damage to the airplane would have been less severe and more people might have survived.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*PLE6CIlyLC0dJEu6.jpg" /><figcaption>The remains of the aft section of the CRJ. (Online Khabar)</figcaption></figure><p>The causes of this accident were on the simple side compared to many I have covered. There were really only three direct causal factors: the incorrect rotation speed, the excessively fast rotation, and the flight crew’s failure to complete the stall avoidance maneuver. One factor that surprisingly had nothing to do with the crash was the cargo loading: despite speculation that improperly secured equipment shifted, leading to an excessively aft center of gravity, the flight data recorder refuted this. If the load had shifted, the pitch of the airplane should have responded to the elevator position in an abnormal manner, but it did not. The horizontal stabilizer, which has been a factor in previous takeoff stall accidents, was also found to have been set correctly.</p><p>Despite these findings, the final report still listed “gross negligence” during loading of the cargo as a contributing factor to the accident. I’m not entirely sure why they chose to do this, but its inclusion has some value insofar as it highlights the real root cause behind all other contributing factors, by which I mean the airline’s casual disregard for rules, regulations, and best practices.</p><p>In addition to flouting rules related to licensing of cargo loaders, carriage of hazmat, cargo restraints, and minimum crew on ferry flights, evidence indicates that the airline was skipping required training items, failing to instill basic competencies in its pilots, and ignoring basic quality assurance procedures.</p><p>Investigators found that the airline’s simulator training syllabus didn’t match the recorded duration of the training, suggesting that some items were skipped. Which items these were is unknown as the report didn’t examine this issue any further. These omissions could potentially explain why pilots were rotating incorrectly and why Captain Shakya failed to react appropriately to the stick shaker. However, the incorrect rotation techniques — and many other issues — could have been caught and corrected using simple quality assurance measures.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/600/1*8dmlVl575IC0hb6scBKkQA.png" /><figcaption>Rescuers work to extract victims from the cockpit. (The Himalayan Times)</figcaption></figure><p>Flight operations quality assurance can be carried out in a number of ways, including but not limited to internal audits, flight data analysis, and collection of anonymous incident reports. At Saurya Airlines, none of those things were occurring. There were no internal audits, no event reporting system (anonymous or otherwise), and no flight data analysis program, even though the required equipment was already in place. The airline claimed to have a safety management system, or SMS, which uses data and reports to identify safety trends and develop corrections, but there were no data or reports to analyze, nor was there any evidence that they were trying to do so. The structure of the company also failed to hold high level staff accountable for safety, except, I assume, for Chief of Safety Sagar Acharya, who seemingly had no objection to boarding (and ultimately perishing aboard) the accident flight.</p><p>The actions of Saurya Airlines and its staff demonstrate that they did not expect to be held accountable for the safety of the service they provided. Furthermore, the deaths of so many of those same staff aboard a flight that should never have been allowed to take off suggests to me that they did not understand the risks they were taking. A culture of disregard for the rules had become so deeply established that Saurya’s management completely lost sight of what a safe airline ought to look like. We could call that “normalization of deviance.”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*Qf1O9XeLr2oKbsYR.jpg" /><figcaption>Investigators examine one of the CRJ’s engines. (AFP)</figcaption></figure><p>The job of the Civil Aviation Authority is to prevent airlines from falling into this kind of intellectual purgatory. Inspections, audits, and ramp checks should reveal that procedures are not being followed, and sanctions should be applied. Unfortunately, this did not occur. The final report suggests that the CAAN simply does not have the staff to carry out these basic functions. The 2023 ICAO audit of Nepal’s aviation authorities also highlighted insufficient training for CAAN inspectors as a point of concern. Both of these problems need to be aggressively resolved if Nepal is to improve its dismal aviation safety record.</p><p>On the other hand, it should not be pretended that Nepal could conjure a world class aviation authority out of nowhere. Nepal is one of 44 states on the United Nations’ list of “least developed” countries, ranking 165th in nominal GDP per capita, although this statistic is improving. At the same time, its aviation sector is quite large for a country of relatively modest size and wealth, resulting in a mismatch between the government’s capability and the level of need. The CAAN — a subdivision of the Ministry of Culture and Tourism — is not equipped to handle the industry it is charged with overseeing, neither in terms of expertise nor funding. But at the same time, increasing funding for the CAAN is a low priority when a third of the country lives on less than US$3.20 per day, and the money that might be used to prevent a plane crash can be (and is being) used to prevent thousands of deaths via expenditures on things like basic sanitation infrastructure and maternity care instead. Under such circumstances, aviation safety might be seen as a bourgeois issue.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1001/0*YUe9uLb05IwDLFPK.jpg" /><figcaption>Rescuers scour the charred remains of the passenger cabin. (The Kathmandu Post)</figcaption></figure><p>Nevertheless, as the importance of tourism to the Nepalese economy increases, and as the country’s still largely rural population swiftly urbanizes, demand for safer transportation is growing and will continue to grow. And money is only half the battle, because the other half is attitude and awareness. That means reorienting the CAAN’s focus to promote a safety culture both among the airlines and within itself. Such a pivot will require not only visionary leadership, but also the nagging voice of a Nepalese NTSB. At present, Nepal does not have an independent accident investigation agency, and each crash is investigated by a specially appointed commission that lacks of the full range of capabilities afforded to a dedicated body. Formed under the Tourism Ministry’s umbrella, these commissions also lack independence and their objectivity is sometimes in question. Furthermore, the depth of accident investigations in Nepal is presently insufficient, as demonstrated by the number of times over the course of this article that I had to use the phrase, “the final report did not explain.” Most of the time, the real root causes of Nepal’s many aviation accidents must be discerned by reading between the lines. If safety is to improve, this kind of dancing around obvious truths must end, and only an independent, politically empowered investigation agency will be able to accomplish that.</p><p>If these steps are taken, then Nepal could achieve safety improvements without diverting money away from the country’s ongoing campaigns to reduce child mortality, improve literacy, install toilets, expand access to clean drinking water, and so on. These campaigns have seen substantial success over the last 20 years, and I have no doubt that a focused effort to improve aviation safety could produce similar results in that sector too. The current system is so underdeveloped that even a small amount of money could instigate real change. But giving that money to the CAAN’s current leadership would be pointless. The mindset at the top has to change first.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4AefAtawEK-JTGnDeI8Q_Q.png" /><figcaption>The best service Saurya Airlines offers. (Saurya Airlines)</figcaption></figure><p>One day after the accident, Saurya Airlines voluntarily suspended operations, for obvious reasons. Later, the CAAN revoked the airline’s operating certificate after concluding that the company was unable to carry out flights due to the loss of the aircraft and most of its maintenance staff. But in one last disheartening twist to the tale, as of April 2025 the airline is trying to get its certificate back. Reportedly, they have been hiring staff to replace those lost in the crash, though who those people are and with what money they were paid is unclear. As of this writing, Saurya Airlines’ website has not been updated, and the page listing its ten management-level staff members still includes five who were on the plane and four who died in the crash. There is also hardly any reason to believe that the company’s safety culture and practices have improved in any meaningful way. Nevertheless, the company chairman told local media in April that he believed the airline was close to restarting operations. To that I will say only two words: god forbid.</p><p>_______________________________________________________________</p><h4>Attention readers!</h4><ol><li>Beginning next week, I will be changing my profile picture. Because my profile picture has been the same for many years, I’m giving a heads up in order to avoid confusion.</li><li>This article did not take me a month to write. The reason it came out only now is because I’m working on two other articles simultaneously. One of them is [redacted] and the other one is Gazpromavia flight 9608, a Sukhoi Superjet that crashed in July 2024 due to improper installation of the angle of attack sensors leading to a fatal sequence of flight envelop protection activations. That promises to be a fascinating case, but I am also professionally translating the Russian-language report, which will take some time. Please check my <a href="https://bsky.app/profile/kyracloudy.bsky.social">Bluesky profile</a> or <a href="https://www.reddit.com/r/AdmiralCloudberg/comments/195loc6/check_the_status_of_my_next_article_here/">this Reddit thread</a> for updates. Thank you!</li></ol><p>_______________________________________________________________</p><p><em>Don’t forget to listen to Controlled Pod Into Terrain, my podcast (with slides!), where I discuss aerospace disasters with my cohosts Ariadne and J! </em><a href="https://www.youtube.com/@ControlledPodIntoTerrain"><em>Check out our channel here</em></a><em>, and listen to </em><a href="https://www.youtube.com/watch?v=-i3dZNFDk84"><em>our latest episode about a titanic battle between a BAC 1–11 and some wind.</em></a><em> Alternatively, download audio-only versions via </em><a href="https://rss.com/podcasts/cpit/"><em>RSS.com</em></a><em>, or look us up on Spotify!</em></p><p>_______________________________________________________________</p><p><a href="https://www.reddit.com/r/AdmiralCloudberg/comments/1mf7klu/how_not_to_run_an_airline_the_2024_saurya/">Join the discussion of this article on Reddit</a></p><p><a href="https://www.patreon.com/Admiral_Cloudberg">Support me on Patreon</a> (Note: I do not earn money from views on Medium!)</p><p><a href="https://bsky.app/profile/kyracloudy.bsky.social">Follow me on Bluesky</a></p><p>Visit <a href="https://www.reddit.com/r/AdmiralCloudberg/">r/admiralcloudberg</a> to read and discuss this series</p><p><a href="https://docs.google.com/document/d/1SeqeoBbVt5jAGO6HWSbNlkAOJ5DNQTDounZW207K714/edit?usp=sharing"><strong>Bibliography</strong></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=3ecd538222d3" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Insidious Truths: The crashes of Birgenair flight 301 and Aeroperú flight 603]]></title>
            <link>https://admiralcloudberg.medium.com/insidious-truths-the-crashes-of-birgenair-flight-301-and-aeroper%C3%BA-flight-603-c7bb6228021b?source=rss-e119a26506e3------2</link>
            <guid isPermaLink="false">https://medium.com/p/c7bb6228021b</guid>
            <category><![CDATA[flying]]></category>
            <category><![CDATA[aviation]]></category>
            <category><![CDATA[technology]]></category>
            <dc:creator><![CDATA[Admiral Cloudberg]]></dc:creator>
            <pubDate>Mon, 30 Jun 2025 08:06:32 GMT</pubDate>
            <atom:updated>2025-09-14T19:49:07.684Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*j6gyodQ3b0EINu35hakekw.png" /><figcaption>The tail section of Birgenair flight 301 lies inverted, 7,200 feet beneath the Atlantic Ocean. (Unknown author, possibly Dominican Republic AIB)</figcaption></figure><p>Speed is the foundation of flight, the invisible hand that holds an airplane in the air, without which it will plummet to its doom. To fly without knowing one’s speed is to drive an automobile without knowing where the edge of the road is. Even worse is to believe in a speed that is false, at which point exiting the great aerial highway becomes all but certain.</p><p>On the 6th of February 1996, the pilots of a Turkish Boeing 757 found themselves in just such a situation moments after takeoff from the Dominican Republic. Climbing through the midnight darkness, they became confused by a faulty airspeed reading and misleading warnings. Unsure what was true and what was false, they lost control of the airplane, which stalled, rolled inverted, and plunged into the Atlantic Ocean, killing all 189 passengers and crew.</p><p>Just eight months later, on the 2nd of October, an Aeroperú Boeing 757 departing from Lima again encountered false speed readings, but this time their altitude was faulty as well. Terrified and confused, unsure where they were going or how fast, the pilots pleaded for help, but there was little anyone could do. After nearly half an hour of chaos, the aircraft descended into the Pacific Ocean, bounced off, turned over, and plowed again into the pitch-black water. Out of 70 passengers and crew, none survived.</p><p>The back-to-back disasters opened the eyes of the aviation industry to the true dangers of what is known as <em>unreliable airspeed</em>. This type of emergency presents unique difficulties that challenge human instincts and corrupt the actions of automated systems. Complete elimination of the diverse causes of unreliable airspeed is all but impossible, as the culprits have included everything from ice to protective covers, insects to masking tape. But in each of the above cases, readily available information could have helped the pilots fly their airplanes safely, despite the loss of crucial speed data. This is the story of two tragedies that resulted from a failure to recognize that fact — and how those tragedies have informed current pilot training and aircraft design.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*YXfl_-Tp6XaG8rKh" /><figcaption>A 2017 advertisement promotes tourism to the Dominican Republic. (Apple Vacations)</figcaption></figure><h3><strong>Part 1: The Turkish Venture</strong></h3><p>◊◊◊</p><p>When people who don’t go on Caribbean vacations try to think of that region’s quintessential destination, they tend to picture Jamaica or the Bahamas, but the current most popular Caribbean island among global tourists is actually the Dominican Republic.* Occupying the eastern half of the island of Hispaniola, the Dominican Republic leads regional tourism in part due to its size, which has allowed the country to position its own beaches and mountains as a more affordable — but no less beautiful — alternative to its smaller and pricier neighbors. That approach began paying dividends in the early 1990s, and tourism to the country has been increasing steadily ever since.</p><p>Historically, Germans were the third most common nationality among tourists to the Dominican Republic, especially during the 1990s. The number of tourists from Germany peaked at over 435,000 in 1999 and has been falling ever since, but during the initial boom, demand for cheap flights between Germany and the Dominican Republic compelled a number of charter airlines to offer such services. One of the smallest and cheapest was the Turkish outfit Birgenair, named for its businessman founder, Çetin Birgen.</p><blockquote>*I actually surveyed my friends for this, asking them to guess the top Caribbean island country or territory by total visitors per year, and included the two most common responses. Nobody guessed the DR.</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/1023/0*ToK11y3KDnuHuJxg.jpg" /><figcaption>Çetin Birgen with a model aircraft in Birgenair livery. (Jurergen Schwarz via Bridgeman Images)</figcaption></figure><p>The story of how a scrappy Turkish airline with less than half a dozen aircraft came to be involved in the long-haul charter business between Germany and the Caribbean is a strange one.</p><p>Since its founding in 1988, Birgenair was involved in the German charter business thanks to a personal relationship between Çetin Birgen and the German-Turkish businessman Vural Öger, owner of the travel agency Öger Tours. The pair started out operating charter flights between Germany and Turkey, but by 1993 their ambitions began to stretch beyond the Atlantic, to the white sand beaches of the Caribbean.</p><p>According to the Freedoms of the Air outlined in the Chicago Convention on International Civil Aviation, an airline may operate a flight from a second country to a third country only for the purpose of connecting to the airline’s home country. Therefore, a charter service ferrying tourists between Germany and the Dominican Republic must be operated by an airline from one of those countries, since the purpose of the flights is not to connect to a third destination. At that time, several German airlines offered services to the Dominican Republic, including Lufthansa subsidiary Condor, which carried numerous tourists on behalf of Öger Tours and countless other travel agencies. But presumably in an effort to undercut his competitors on price, Öger wanted the ability to book his customers on the much cheaper Birgenair instead. It has also been alleged that Öger owned a financial stake in Birgenair, but this is disputed.</p><p>Fortunately for Öger and Birgen, there is a well-known solution to this type of international business problem: establish a shell company.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vLxA_Kbbu-Or9zBh6ODyXA.jpeg" /><figcaption>Birgenair’s Boeing 767 wearing the livery of its Dominican client airline Alas Nacionales. (Airlinerphotos.de via flickr)</figcaption></figure><p>In 1995, apparently at the behest of Öger Tours and Birgenair, Finnish businessman Matti Puhakka and six unnamed Dominican investors established an airline in the Dominican Republic named Alas Nacionales (“National Wings”), which was granted a Dominican Air Operator Certificate (AOC) despite having no aircraft. This airline then entered into a lease agreement with Birgenair, under which Birgenair would supply aircraft to fly between the Dominican Republic and Germany under Alas Nacionales’ brand and AOC. According to German newspaper Die Zeit, Puhakka and the other investors received a flat fee for each passenger carried under this arrangement.</p><p>In reality, of course, Alas Nacionales only existed on paper. Die Zeit described the airline as a “mailbox company” (<em>Briefkastenfirma)</em>. After the accident, German reporters attempted to track down this airline, and found the company headquarters inside an unmarked, dilapidated building on the outskirts of Santo Domingo, staffed by an individual who was unable to produce a business card. It is quite apparent that Alas Nacionales was nothing more than the local face of Birgenair, a legal fiction that allowed Birgenair to operate out of the country without connecting to Turkey. However, this arrangement wasn’t illegal, and Birgenair was far from the first or last airline to do it.</p><p>After setting up Alas Nacionales, Birgenair leased a Boeing 767 to its Dominican partner, which was re-registered in the Dominican Republic as HI-660CA. The word “Birgenair” was hastily painted over with the name “Alas Nacionales,” but the livery otherwise remained unchanged. Flight crews were apparently hired by Alas Nacionales directly from Birgenair. Regular nonstop flights between the Dominican Republic and Germany started shortly after.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*VL4QIAyklgr0HEQs" /><figcaption>Birgenair’s Boeing 757, TC-GEN, the aircraft involved in the accident. (Klaus Brandmaier via flickr)</figcaption></figure><p>At the same time, beginning in November 1995, Birgenair took advantage of its position in the Dominican Republic to lease a second aircraft, a Boeing 757 with the registration TC-GEN, to Argentine charter company Servicios de Transportes Aéreos Fueguinos, known as STAF Airlines, for irregular flights between the Dominican Republic and Buenos Aires. Very little information about this operation is available. However, it is apparent that this was what’s known as a “wet lease.”</p><p>In aviation, a dry lease is a lease in which the lessor supplies an aircraft to the lessee, while the lessee provides their own crew. The 767 lease to Alas Nacionales was technically a dry lease, because the crewmembers worked for the lessee. By contrast, in a wet lease, the lessor supplies both the aircraft and crew, while the lessee sells the tickets and pays the operating expenses. Airlines typically use wet leases to cover short-term gaps in their fleets and schedules.</p><p>A dry lease and a wet lease are legally very distinct because in a wet lease, the lessor remains the legal operator of the aircraft. Therefore, the 757 remained registered in Turkey, remained painted in Birgenair colors, and remained on Birgenair’s AOC.</p><p>Very little is known about Birgenair’s wet lease to STAF Airlines. Wikipedia states that Birgenair only operated five flights on behalf of STAF between November 1995 and January 1996, but this number isn’t in the cited source. What is known is that after the last flight in January, the aircraft sat unused on the apron in the northern Dominican city of Puerto Plata for an uncertain period of time. Dominican investigators would later state that it remained parked for 20 days beginning on January 17th, while Birgenair stated that it was parked for 12 days beginning on January 25th.</p><p>It just so happens that Puerto Plata was one of the cities served by Birgenair through its front company Alas Nacionales. In fact, the city is one of the most popular tourist destinations in the Dominican Republic, with 162,000 residents and tens of thousands of hotel beds, including high-end resorts. Puerto Plata also features a cruise port and an international airport, located on the coast a few kilometers east of the city. Today, Puerto Plata’s Gregorio Luperón International Airport is the fourth busiest in the Dominican Republic with over 700,000 passengers arriving and departing from its single runway every year aboard airlines like WestJet, TUI Nordic, and Edelweiss.</p><p>It was here that a deadly sequence of events took place on the night of the 6th of February, 1996.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*lUzaMa7-9nQ68w2s.jpg" /><figcaption>A size and scale comparison of the Boeing 767 vs the Boeing 757. (AerospaceWeb)</figcaption></figure><p>On that evening, crews were preparing the Boeing 767 to operate Alas Nacionales flight 301 from Puerto Plata to Frankfurt via Berlin when they discovered that a hydraulic pump wasn’t working. As this was a no-go item and an immediate repair could not be conducted, Alas Nacionales contacted Birgenair to arrange a last minute switch to that airline’s idle 757 instead.</p><p>The Boeing 767 is a wide body, twin-aisle, twin engine aircraft with seating for between 214 and 290 passengers depending on the configuration. The 767–200ER, the variant operated by Birgenair and Alas Nacionales, was capable of flying nonstop from Puerto Plata to Berlin.</p><p>By contrast, the Boeing 757 is a twin-engine narrow body aircraft with a shorter range and a capacity of 200 to 239 passengers for the -200 variant operated by Birgenair, depending on the configuration. The 757–200 was not capable of flying nonstop to Berlin, but it was large enough to accommodate the 176 passengers scheduled to depart that night. As a result, Birgenair agreed to operate the flight using the 757 on behalf of Alas Nacionales, with a fuel stop in Gander, Newfoundland hastily added to the flight plan.</p><p>This replacement flight was operated on Birgenair’s AOC and had to use a Birgenair crew. Although the 757 and 767 have a high degree of system commonality, allowing pilots to fly both types at the same time, my assumption is that it was not possible to switch the original crew over to the new aircraft because the original crew officially worked for Alas Nacionales, not Birgenair. Furthermore, even if this was possible, the original crew might not have been able to fly until the next day, depending on how long it had been since they were called up for duty.</p><p>Fortunately, Birgenair had its own full 757 crew already in place in Puerto Plata who had not flown since January 27th. It’s not clear from official documents how they got to Puerto Plata, or why. One would assume that they had been flying the wet lease flights to Buenos Aires, but the last such flight occurred no later than January 25th. Some other flight must have taken place on the 27th but I can’t say where, or how. Regardless, the pilots and flight attendants had been stuck in the Dominican Republic for at least 10 days by this point, and they probably welcomed an opportunity to return home. What would have been less welcome was the short notice callup, which came in just after 21:00 local time. Without advance notice of the flight, they might not have spent time resting up for the late night departure, so I can’t imagine they were too thrilled by the idea of spending the rest of the night flying to Europe instead of sleeping.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/411/0*R9vPVP9NrYmO_XJp.png" /><figcaption>The Turkish crewmembers of Birgenair flight 301. As this collage comes from a Turkish newspaper, two Dominican flight attendants appear to have been excluded. (Unknown Turkish newspaper)</figcaption></figure><p>For a flight of this length, an augmented crew was required, with a third pilot who would rotate in part way through the flight. In command of this three-man crew was 61-year-old Captain Ahmet Erdem, a highly experienced pilot with 24,750 flying hours over a lengthy career, including 1,875 hours on the 757.</p><p>His first officer for the first part of the flight would be 34-year-old Aykut Gergin, whose 3,500 hours made him no longer new to flying, but he was new to the 757, with only 71 hours on type.</p><p>Later on, the plan was for Erdem to go off duty, at which point he would be replaced by the third pilot, 51-year-old Relief Captain Muhlis Evrenesoglu, who had a substantial 15,000 flying hours, but once again, very few — 121 to be precise — on the 757.</p><p>Finally, at some point before the end of the flight, Captain Erdem would return to relieve First Officer Gergin, and the two captains would finish the journey together.</p><p>In addition to the three pilots, the crew included six flight attendants and four maintenance engineers, who had also been on standby for a considerable period of time before Birgenair’s last-minute callup. Together, they would oversee the boarding of the 176 passengers, who were mostly Germans on a package vacation sold by Öger Tours. Two passengers were also sitting members of the Polish legislature.</p><p>By approximately 23:15 local time, all 13 crewmembers had arrived at the aircraft and the passengers were ushered on board. In the meantime, the pilots completed the pre-flight walkaround and checks, which confirmed that the 757 was seemingly in good working order despite its lengthy downtime.</p><p>Little did they know that this conclusion was wrong.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*fSRHDjS1LFTqUikY.jpg" /><figcaption>An exemplar pitot tube. This one is from an Airbus A380 and has an angle of attack vane attached as well. (David Monniaux)</figcaption></figure><p>When an aircraft is parked for an extended period of time, several routine maintenance actions must take place to ensure that it remains airworthy. Specifically for the purposes of this story, it bears mentioning that all external sensors and the engine inlets should be covered to prevent environmental contamination.</p><p>A modern aircraft relies on an extensive network of sensors that monitor everything from air pressure to exhaust temperature to angle of attack. But for now I want to focus on the sensors that measure airspeed and air pressure.</p><p>The ambient or static air pressure is a parameter used by modern aircraft in numerous critical processes, including but not limited to calculating barometric altitude and airspeed. This pressure is measured at the static ports, a series of sensors installed flush with the fuselage on the 757’s forward underside. Redundant static ports independently supply pressure data to the captain’s and first officer’s instruments, as well as the set of emergency standby instruments on the center console.</p><p>An airplane’s airspeed, its speed relative to the surrounding air, is crucial to stable flight. Except during landing, knowing one’s speed relative to the ground is of little use because the amount of lift generated by the wings depends in part on the speed of the airflow over them, which can be affected by motions of the air mass itself — that is to say, wind. Therefore, the actual airspeed is approximately equal to the groundspeed plus the headwind component, or minus the tailwind component.*</p><blockquote>*This breaks down a bit at high altitudes but the flight in this story never got high enough for that to matter.</blockquote><p>Airspeed is measured using three independent sets of pitot tubes. As air flows into the pitot tubes, it exerts pressure against a sensor, which is then compared against the static pressure to calculate the speed of the airplane relative to the surrounding air mass. The resulting value is then depicted on each pilots’ airspeed indicator, located just to the left of the artificial horizon on the 757.</p><p>The raw data from the 757’s pitot tubes and static ports is processed and integrated with other parameters by three redundant air data computers, or ADCs. If one of the three airspeed indicators displays an erroneous value, the pilots can change its data source to a different ADC using the corresponding data source selector.</p><p>There are a number of reasons why an airspeed indicator might display erroneous values, but typically this is because something has blocked one or more pitot tubes. For instance, ice accumulation inside the tube during flight can reduce the amount of air reaching the sensor, resulting in a lower flow pressure and an erroneously low indicated airspeed. Alternatively, if the flight takes off with an already existing pitot tube blockage, sea-level air can become trapped inside the tube. The measured pressure then becomes a constant, while the static pressure decreases, resulting in an airspeed indication that starts out at zero, but increases proportionally with altitude.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1000/1*t_jFDiPghyMaUYgF5aP1xA.png" /><figcaption>A pitot tube with a cover applied. (Sesame technologies)</figcaption></figure><p>In order to reduce the probability of such a blockage, special pitot tube covers must be applied whenever an aircraft is expected to remain parked for a certain period of time. Later, the parties involved in this story failed to agree on exactly how long an aircraft had to be parked before covers were required by the maintenance manual. Birgenair, for its part, cited “irritating and even conflicting procedures” that seemingly gave permission to omit pitot tube covers for some period of time ranging from seven days to two months, depending on the interpretation. However, it is accepted that contamination of the pitot tubes can occur when an aircraft is parked for <em>any</em> length of time, a fact which Birgenair also acknowledged.</p><p>It is not known whether or for how long pitot tube covers were used during the period of time in which TC-GEN was parked at Puerto Plata. Dominican investigators would later write that there was no evidence that pitot tube covers were used at any point during that period. On the other hand, Birgenair stated that pitot tube covers were in fact used up until approximately the 4th of February, when a routine engine runup was conducted, presumably in order to maintain the airplane’s flight-ready status. It is however undisputed that from that point onward, no pitot tube covers were installed. Çetin Birgen, writing on behalf of his airline, stated that Birgenair’s mechanics in Puerto Plata decided not to reapply the covers because they expected the aircraft to be ferried back to Europe within three days, which they believed was permissible under the relevant provisions of the maintenance manual.</p><p>If Birgenair is to be believed, then the aircraft stood without pitot tube covers for approximately two days before it was requisitioned to complete the flight to Berlin. Unfortunately, history has shown that this is plenty of time for the pitot tubes to become blocked by a particularly sneaky little villain — the mud dauber wasp.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/800/0*z9CV5HySxNhEvCgy.jpg" /><figcaption>A Sceliphron caementarium individual with its nest. (University of Florida)</figcaption></figure><p>Mud daubers are a collection of wasp species from several taxonomic families that are subjectively united by their habit of building simple tubular nests out of mud. The species <em>Sceliphron caementarium</em> is native to North and Central America, and like many mud daubers, it prefers to build its nests inside existing crevices and holes, where it carefully constructs a separate mud tube for each individual egg. The inside of a pitot tube happens to be the perfect place for such a nest, at least from the wasp’s perspective. From our perspective, however, it’s less than ideal. In fact, several previous accidents and incidents have been tentatively or conclusively attributed to unreliable airspeed indications caused by mud dauber nests inside the pitot tubes, including the crash of Florida Commuter Airlines flight 65, a DC-3 that went down off the coast of Florida in 1980 with the loss of 34 passengers and crew.</p><p>Other incidents have shown that mud daubers can commandeer an aircraft’s pitot tubes within a very short period of time. In perhaps the most extraordinary example, in 2013 an Etihad Airways Airbus A330 made an emergency landing after takeoff from Brisbane, Australia due to unreliable airspeed indications caused by the presence of a mud dauber nest inside the captain’s pitot tube. Even though the aircraft was only on the ground in Brisbane for two hours before the incident flight, that was apparently enough time for a mud dauber to claim the pitot tube as its sovereign territory.</p><p>Given these precedents, and the lack of alternative explanations, is believed — but not proven or provable — that a mud dauber most likely built a nest inside the captain’s pitot tube while TC-GEN was parked at Puerto Plata without pitot tube covers. This conclusion remains in the realm of supposition rather than fact because no living soul ever again laid eyes on the pitot tubes after the aircraft departed, but I’ll provide some more information about why a mud dauber is the preferred theory at the end of Part 1.</p><p>In any case, because the effects of a blocked pitot tube only become apparent once the aircraft is travelling at speed, there was very little if any opportunity to detect the blockage prior to getting underway. Although the pre-flight inspection represented an opportunity to check for obvious problems, it would have been impossible to see a mud dauber nest or any other contaminants inside the pitot tubes, because the probes are high off the ground and have very small openings.</p><p>For this reason, Boeing’s maintenance procedures recommended a more specific verification of the pitot-static system prior to returning a parked aircraft to service. The accident report doesn’t say what equipment was required to perform such a verification on a Boeing 757, but Çetin Birgen contends that this technology was not available at the poorly equipped Gregorio Luperón International Airport.</p><p>Consequently, the pilots concluded that the aircraft was airworthy and accepted it for flight, unaware that the captain’s pitot tube was blocked.</p><p>◊◊◊</p><p>At 23:42 local time, Birgenair flight 301 lined up for takeoff on Puerto Plata’s runway 08, with Captain Erdem at the controls. The weather was unsettled but not adverse, with one fourth overcast at 1,800 feet, near full overcast at 7,000, and intermittent rain over the field. Thunderstorms churned in the distance, over the ocean.</p><p>The pilots advanced the thrust levers to takeoff power, and First Officer Gergin called “power’s set.” The aircraft began to accelerate down the still-wet runway, propelled forward by the 757’s famously overpowered engines.</p><p>Within seconds, the aircraft reached the 80-knot checkpoint, and First Officer Gergin called, “80 knots.” But because Captain Erdem’s pitot tube was blocked by the mud dauber nest, it did not measure the increasing airspeed, prompting Erdem to exclaim, “My airspeed indicator’s not working.”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/748/1*Jqpq-NXUK147Pnq5niKDuA.jpeg" /><figcaption>The configuration of the 757–200’s pitot-static system and flight instruments. (FAA)</figcaption></figure><p>This sudden problem at the utmost outset of the flight could have prompted a variety of responses, but there was and remains no single right answer. Below 80 to 100 knots — the exact value depends on the aircraft — pilots are taught to reject a takeoff for any failure or warning indication. There is no risk in rejecting a takeoff at these speeds due to the size of the remaining runway margin and the relatively minimal demand on the brakes.</p><p>But above this threshold lies the “high speed regime,” where a narrower set of conditions restricts the decision to reject. Between 80–100 knots and decision speed, or V1, pilots are generally taught to reject the takeoff only in the event of an engine failure, fire, objects on the runway, windshear warning, or — crucially — whenever the pilots judge that the aircraft is “unsafe to fly.” This last point brings in a level of subjectivity that can lead to disagreement over the best course of action if an unexpected scenario arises.</p><p>There was no specific policy requiring the crew to reject the takeoff due to the failure of one out of three airspeed indicators, which means that the decision was left to the pilots’ judgment. In this case, First Officer Gergin’s “80 knots” callout indicated that the aircraft was entering the high speed regime, which begins at 80 knots on the 757. It was only at this point that the airspeed issue was detected.</p><p>In the opinion of the eventual investigation, the ideal action upon discovering an airspeed indication problem at 80 knots would be to reject the takeoff immediately. But in order to reject the takeoff in the high speed regime, the pilots would need to determine that the failure threatens the safety of the aircraft. And if too much time is taken to evaluate the significance of the failure, the aircraft could surpass V1, at which point they would have no choice but to continue into the air, because the remaining runway would be insufficient to stop the airplane.</p><p>In fact, by the time Captain Erdem acknowledged that his airspeed indicator was not working, the aircraft was already traveling at almost 100 knots. First Officer Gergin then affirmed that Erdem’s airspeed indicator was indeed not working, after which he called out, “one twenty.”</p><p>“Is yours working?” Captain Erdem asked.</p><p>“Yes sir,” Gergin affirmed.</p><p>By this point the aircraft was traveling at 132 knots, and V1was rapidly approaching. Therefore, Erdem had only a couple of seconds to decide whether this failure rendered the aircraft “unsafe to fly.” But from his perspective, the answer was probably obvious: since First Officer Gergin’s airspeed indicator was working, then a valid indication existed, and safe flight was possible. He also would have needed to weigh the risk posed by the failure against the inherent risk of rejecting close to V1, especially on a wet runway with no overrun safety area, only a jumble of boulders sloping down into the Atlantic Ocean.</p><p>In the end, Captain Erdem did not decide to reject the takeoff. It was a decision that many have questioned, but under closer scrutiny it appears understandable. He certainly could not have anticipated the dire sequence of events that would follow. So he said to his first officer, “You tell me,” with the understanding that they would use the first officer’s airspeed readout until further notice.</p><p>At 23:42 and 35 seconds — nine seconds after Erdem called out “My airspeed indicator’s not working” — First Officer Gergin announced “V1,” and then “Rotate.” Captain Erdem rotated for takeoff, and flight 301 lifted off the runway in a normal manner.</p><p>Erdem called out, “Positive climb, gear up,” and Gergin confirmed they were climbing, then raised the landing gear.</p><p>“Gear is up,” he announced. He then asked whether Erdem would like the autopilot to be configured in LNAV mode, to which Erdem replied, “Yes please.”</p><p>At this point, the autopilot was not actually engaged, nor would it be engaged for another two minutes. However, setting the desired modes before engaging the autopilot ensures that it engages in the desired configuration. In this case, the crew wanted to use the LNAV mode in the autopilot’s lateral channel, which would cause the autopilot to steer the plane along the series of flight plan waypoints entered in the flight management computer (FMC). Therefore, First Officer Gergin pressed the LNAV button and called out the selection, which Erdem acknowledged.</p><p>Just one second later, Gergin announced, “It began to operate.” But what was he referring to?</p><p>This line, translated from Turkish, appears to have been widely misinterpreted and/or misattributed. The final report on Birgenair flight 301, which is supposed to be the definitive account of events, attributes this line to Captain Erdem, and every single retelling in the three decades since has repeated this. But in his comments on the report, Çetin Birgen points out that according to the official cockpit voice recorder transcript, this line was actually uttered by First Officer Gergin — and the transcript, which I have viewed, confirms that Birgen was correct and the Dominican investigators were wrong.</p><p>Having misattributed this line, the final report states that Erdem was referring to his airspeed indicator, which had indeed begun to operate, in a sense. Because the mud dauber nest had trapped a pocket of sea level air inside the captain’s pitot tube, and because ambient pressure decreases with altitude, the difference between the pressure inside the tube and the static pressure outside the airplane was now increasing as the aircraft climbed. This change manifested as an increasing airspeed indication, but the parameter actually being measured was effectively altitude, not airspeed. By the time the comment in question was made at around 500 feet above ground level, the captain’s airspeed indication had increased to 125 knots and was rising at a rate of about 4 knots per second. However, the actual airspeed was likely around 200 knots.*</p><blockquote>*Note: the flight data recorder only recorded the captain’s airspeed indication, so no accurate record of airspeed was available from the flight. However, the recorded ground speed was 196 knots at this time, with a slight headwind.</blockquote><p>On the other hand, the discovery that the First Officer Gergin actually uttered this crucial line complicates the narrative. It follows that either he was glancing over at the captain’s airspeed indicator, or he was referring to something else entirely — but what? In his response to the accident report, Birgen argued that Gergin meant that LNAV mode had successfully engaged, and that the comment had nothing to do with airspeed at all. However, in my opinion it would be pretty strange to say that LNAV “began to operate” when the autopilot was off, because LNAV mode wasn’t <em>doing</em> anything — it was just sitting there, waiting.</p><p>It’s also possible that the line was poorly translated from Turkish, and in fact Birgen did write that some lines were translated improperly, but he didn’t specify which lines he was talking about. The original Turkish language transcript is not available and I don’t speak a word of Turkish, but I do have academic knowledge of linguistics and translation more generally, and it’s not inconceivable that a phrase best translated as “it has engaged” could be misleadingly rendered as “it began to operate.” But if this line is accurate, then I would prefer the explanation that Gergin was keeping an eye on Erdem’s airspeed indicator and called out when he saw it start working.</p><p>In either case, Erdem didn’t acknowledge the first officer’s callout, and two seconds later he asked Gergin to turn off the windscreen wipers, proving that his mind was elsewhere. So far there was no evidence that Erdem had lent any credence to his airspeed indications, despite the investigators’ assertions to the contrary.</p><p>Instead, flight 301 continued its climb without any signs of trouble. At 1,000 feet, Erdem called for the thrust to be reduced from takeoff to climb power, and Gergin acknowledged. He then called on Gergin to set the autopilot’s vertical mode to VNAV, which he did. Gergin then reported that they had reached flap retraction speed, which they had, and Erdem instructed him to set flaps 5, then flaps 1, then flaps up. At the same time, the Puerto Plata tower controller handed them over to Santo Domingo area control. Moments later, at 23:43 and 48 seconds, Gergin called the after takeoff checklist complete.</p><p>Next, Gergin called Santo Domingo to report their position. The controller replied with an instruction to climb to 28,000 feet and report passing waypoint Pokeg, which Gergin read back correctly.</p><p>Finally, at 23:44:07, while climbing through 3,500 feet over the ocean, Captain Erdem called for Gergin to engage the autopilot. Specifically, he asked for the center autopilot — the 757 has three; left, right, and center — but this would have no practical impact on the sequence of events.</p><p>On many modern aircraft, especially fly-by-wire aircraft, the extensive automation suite draws its flight data in aggregate form from several redundant air data computers that compare the raw data sources and reject any source that doesn’t agree with the others. But the Boeing 757–200, designed in the late 1970s and in service since 1982, did not have this capability. While it was among the first aircraft to come with a heavily computerized cockpit, these computers didn’t automatically compare inputs to reject faulty data sources, and the automation could only draw data from one set of sensors at a time, rather than aggregating data from two or three sources. In fact, by default, the left and center autopilots used the №1 air data computer as their data source, which was supplied by the captain’s static ports and pitot tubes.</p><p>As you may have already guessed, this meant that the autopilot had no source of airspeed data other than the captain’s blocked pitot tube. Furthermore, the readings could not be rejected as invalid because the analog sensor was measuring the actual local pressure inside the tube, which was then reported faithfully to the air data computer. Consequently, the autopilot immediately began to control the airplane based on the captain’s incorrect airspeed indications.</p><p>The significance of this fact is sometimes lost in retellings of the Birgenair story. It was crucial to the sequence of events, but the final report didn’t quite convey its importance, despite acknowledging its role. What in fact took place here was a failure of technical knowledge. The captain — knowing full well that his airspeed indicator was not working — lacked sufficient understanding of his highly computerized aircraft to predict that this false information would be fed to the center autopilot, and that the autopilot would react to that information as though it were true. To a modern pilot trained from the outset on modern aircraft, this fact would be self-evident, but to Captain Erdem, it was not.</p><p>As soon as the autopilot engaged, it began to navigate laterally according to the programmed flight plan (LNAV). But in order to navigate vertically (VNAV), it needed to configure the aircraft to achieve the programmed altitude, and to do that, it activated a secondary mode called flight level change, or FLCH. This is a mode common to Boeing aircraft in which the autothrottle commands continuous thrust (climb thrust, in this case) while the autopilot adjusts pitch to maintain a constant airspeed, resulting in the optimal rate of climb up to the selected flight level. Pitching up slows the aircraft down; pitching down speeds it up.</p><p>In this case, the actual selected speed isn’t that important — it was presumably a normal cruise speed, somewhere between 220 and 250 knots. But as the airplane climbed, the captain’s indicated airspeed kept increasing proportionally with altitude until it exceeded the target airspeed. And with the autopilot’s vertical channel in flight level change mode and the thrust levers locked at climb power, the autopilot responded to the increasing airspeed by pitching up in order to slow down. This pitch up was slow at first, but pitching up also caused the plane to climb faster, which caused the difference between the trapped pitot air and the static pressure to increase faster, which caused the indicated airspeed to rise faster, which caused the autopilot to pitch up more… and you can see where this is going.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/300/1*GmWhuqEZZAOLYFSmbviDxg.jpeg" /><figcaption>The EICAS as it would have appeared following the generation of the two caution messages. (FAA)</figcaption></figure><p>As the airspeed readings increased, but before the pilots had a chance to realize what was occurring, two mysterious caution messages appeared on the screen of the Engine Indicating and Crew Alerting System, or EICAS. These messages read “rudder ratio” and “mach/speed trim.”</p><p>The first message, rudder ratio, was produced by a system that adjusts the ratio of rudder pedal deflection to actual rudder deflection with respect to airspeed. The purpose of this system is to ensure a consistent aircraft response to a given pedal deflection at all speeds, even though the effectiveness of the control surfaces actually increases proportionally with airspeed.</p><p>The second message, “mach/speed trim,” came from a system that subtly adjusts the position of the horizontal stabilizer to compensate for the tendency of the aircraft’s center of lift to move aft at high Mach numbers (that is, closer to the speed of sound).</p><p>As far as I can tell, both of these systems took into account airspeed and Mach number information from either all three pitot-static systems, or from a pitot-static system other than №1. This matter is purely academic but if anyone happens to know which is the case, please let me know. Regardless, these systems continued to function normally with respect to the aircraft’s actual airspeed, but because the captain’s indicated airspeed was very high, caution messages were generated to warn the flight crew that there was a discrepancy between the indicated airspeed and the settings of the rudder ratio and Mach trim systems. The designer’s intention was that these messages would indicate a failure of the aforementioned systems, but in this case it actually meant that the messages were generated by a computer that was getting the wrong airspeed information.</p><p>None of the pilots aboard Birgenair flight 301 had been taught that these caution messages could be the result of an erroneous airspeed indication. In fact, they probably had very little understanding of what the messages referred to at all. Clearly confused, Captain Erdem simply read out, “Rudder ratio? Mach airspeed trim?”</p><p>“Trim, yes,” said First Officer Gergin.</p><p>“There is something wrong, there are some problems,” Erdem cryptically declared.</p><p>For 15 seconds, Gergin clarified a clearance with air traffic control. But as soon as that conversation ended, Erdem repeated, “Okay, there is something crazy, do you see it?”</p><p>Presumably he pointed at his airspeed indicator, because Gergin replied, “There is something crazy there, at this moment two hundred only is mine and decreasing sir.” Indeed, as the autopilot steadily pitched up to counter the ever increasing indicated airspeed, the actual airspeed — which was still displayed correctly to the first officer — began to decrease below the target value.</p><p>The correct action at this point would have been to disconnect the autopilot, establish a stabilized flight path, then evaluate which airspeed was correct by comparing to the standby airspeed indicator on the center console. But even this may have been unnecessary if the pilots had simply trusted their previous determination that the captain’s indicator was faulty.</p><p>If the crew had previously noticed the captain’s airspeed indicator coming to life, then this could have complicated their assessment. For a brief period after Gergin stated “it has begun to operate,” the captain’s airspeed indicator happened to display an airspeed that was quite close to the correct value. The final report endorses the theory that this false sense of normalcy caused the pilots to believe that the problem had corrected itself. However, I’m skeptical of that assumption because of Captain Erdem’s bombshell reply: “Both of them are wrong. What can we do?”</p><p>In my opinion, if Erdem believed his own airspeed indicator was correct, then he wouldn’t have announced that both indicators were wrong. Rather, I think he knew all along that his airspeed was incorrect, but falsely believed that the autopilot was now maintaining the selected speed, due to an incomplete understanding of the 757’s air data distribution architecture. So when Gergin announced that his airspeed indicator showed 200 knots — well below the target speed and decreasing — Erdem’s first assumption was that something was now wrong with Gergin’s airspeed indicator too.</p><p>It may seem obvious, from the vantage point of 2025, or whatever year it is when you’re reading this, that a faulty airspeed indication is probably caused by bad data, and that this bad data will also be fed to other aircraft systems. But in 1996, the transition to highly computerized aircraft was still underway in most of the world, and unreliable airspeed emergencies on these aircraft were not widely understood. The vast majority of Captain Erdem’s 24,000 flying hours were spent on a variety of 1950s-era and 60s-era aircraft, including the Vickers Viscount, Douglas DC-8, Douglas DC-9, Boeing 707, and Boeing 727. Pilots transferring from these aircraft to “glass cockpit,” computer-heavy aircraft like the Boeing 757 at that time were not necessarily taught to understand the complex interplay between the sensors and computers that controlled the aircraft’s automation technology and digital flight displays. <a href="https://admiralcloudberg.medium.com/a-mathematical-miracle-the-story-of-air-canada-flight-143-or-the-gimli-glider-9e99545d9b3d">As I previously discussed in my article on the infamous Gimli Glider</a>, much of this interplay was not considered “need to know” information. As a result, I think it’s possible that Erdem’s instinct upon seeing an erroneous instrument indication was to assume that the <em>instrument itself</em> was faulty, without considering the implications of a fault with the <em>data source.</em> But that’s simply my untested opinion.</p><p>Without this understanding, Captain Erdem found himself facing a confusing barrage of indications that seemed to lack any obvious common origin. He almost certainly didn’t understand why the rudder ratio and mach/speed trim caution messages appeared, nor for that matter would most 757 pilots at the time. And he had lost faith in his instruments too, because neither pilot’s airspeed indicator matched his conception of what the plane <em>should</em> be doing.</p><p>Erdem had been flying for long enough to know that there was no checklist for this situation. So what was he to do? In the event, his fallback response was to declare, “Let’s check the circuit breakers.”</p><p>Unfortunately, this was not an appropriate response to the indications he was receiving. The circuit breakers might be relevant if a digital instrument has gone completely blank, but not when the instrument is displaying wrong information. It should also go without saying that messing with circuit breakers in flight, without following an emergency procedure, is not a course of action envisioned by the manufacturer and should be attempted only as an absolute last resort, if at all.</p><p>In response to Erdem’s call to check the circuit breakers, Gergin said, “Yes,” but before he could actually do so, Erdem announced, “The alternate is correct.”</p><p>In his own submission, Çetin Birgen wrote that this line was actually spoken by the relief captain Evrenesoglu, but the cockpit voice recorder transcript doesn’t confirm this. In the absence of any primary evidence indicating otherwise, I’ve attributed this line to Captain Erdem, as does the final report. But regardless of who said it, there are two possible interpretations of this line that lead to very different conclusions about what may have happened next.</p><p>According to the final report, Erdem was most likely referring to the standby or alternate airspeed indicator on the center console. This instrument was indeed showing the correct airspeed value, which was identical to the first officer’s value. However, it’s apparent that Erdem did not use the standby airspeed indicator as a reference, nor did he cross-check it against either of the other airspeed indicators, as would be expected in the event of an instrumentation problem.</p><p>In his submission, Birgen argued that according to the standard phraseology used by Birgenair pilots, the word “standby” would be used to describe the standby instruments, while the word “alternate” would refer to the alternate data source. Therefore, he proposed that the person who spoke this line was not referring to the standby airspeed indicator, but was actually suggesting that the problem might be solved by switching one of the data source selector switches to “alternate.”</p><p>During my research, I found it difficult to evaluate which of these interpretations was more likely to be correct, and there are arguments against both. For instance, if Erdem had determined that the standby airspeed indicator was correct, then why didn’t he use it as his airspeed reference? Without getting too far ahead of myself, it’s apparent that at no point after this statement did Erdem accurately determine their airspeed. But if he meant to suggest the use of an alternate data source, then why didn’t he move his data source selector switch to “alternate,” which would have caused his instruments to draw correct data from the №2 ADC?</p><p>Birgen argued in his submission that at time 23:44:16, about 40 seconds before someone said “alternate is correct,” captain Erdem briefly switched his air data source selector to “alternate,” then moved it back again because the indication still didn’t match his mental model of what the aircraft was doing. However, I concluded that this was not true. The raw flight data from the FDR did show that the captain’s air data selector switch was positioned at “alternate” for 1 second at 23:44:16, but the investigation determined that the data from that particular second was corrupted and could not be used. In fact, during that exact second a large number of parameters recorded unreasonable or obviously false values, including a roll angle of 179 degrees, a 50% drop in engine fan rotation speed, a 50% decrease in airspeed and altitude, a ground speed of 500 knots, and an angle of attack of 45 degrees. All of these parameters returned to normal values by 23:44:17, as did the air data switch position. It can therefore be stated with a high degree of certainty that Captain Erdem did not touch his air data switch at that point, nor did he do so at any other time during the flight, according to the FDR.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8OYu67DtMcmZxPu8o3_Nug.png" /><figcaption>The highlighted line, corresponding to time 23:44:16 (03:44:16 UTC), contains obviously false data, casting severe doubt on Birgen’s assertion that the captain switched his air data source selector (“ADC switch”) to alternate (“Rt.”). Note that although the title says “preliminary,” my analysis of the accident is also based on the final, non-preliminary data, but only the preliminary data contains the captain’s air data switch position. (AIB Dominican Republic)</figcaption></figure><p>However, Birgen also argues that when Evrenesoglu — according to the transcript, actually Erdem — announced “alternate is correct,” First Officer Gergin mistakenly reacted by moving <em>his</em> air data switch to “alternate.” This would have caused his instruments to draw incorrect airspeed data from ADC №1. And while he should have known in theory that this would happen, it’s already clear that the pilots of flight 301 did not understand the 757’s air data architecture, and he might not have realized that moving the air data switch to “alternate” causes his instruments to draw data from the other pilot’s ADC, rather than from the third, standby ADC.</p><p>Unfortunately, this hypothesis is impossible to prove beyond doubt because the flight data recorder did not record the position of the first officer’s air data switch, only the captain’s. Nevertheless, as we will soon see, it’s a possibility worth considering.</p><p>Immediately after Erdem called out “alternate is correct,” First Officer Gergin affirmed, “The alternate one is correct.” Birgen’s submission claims this line was spoken by Captain Erdem, but the transcript contradicts this.</p><p>Erdem then said, “As [the] aircraft was not flying and on [the] ground, something happening is usual. Such as an elevator asymmetry and other things.” Indeed, it is common for issues to arise while an aircraft is parked for a long time.</p><p>He then declared, “We don’t believe them.” Most likely he was referring to the caution messages on the EICAS display, but he might have been referring to the airspeed indicators as well; it’s hard to say.</p><p>Meanwhile, Relief Captain Evrenesoglu asked, “Shall I reset its circuit breaker?”</p><p>“Yes, reset it,” Erdem agreed.</p><p>“To understand the reason,” Evrenesoglu continued.</p><p>“Yeah,” said Erdem.</p><p>Seconds later, at 23:45:28, the overspeed warning suddenly burst to life, filling the cockpit with an ominous rapid-fire clacking sound. The warning was based on the captain’s airspeed indication, which had now risen to 353 knots, above the maximum operating speed of the aircraft. Meanwhile, the actual airspeed was below 200 knots and falling.</p><p>Correctly recognizing that the warning was based on a false indication, Captain Erdem stated, “Okay, it’s no matter. Pull the airspeed, we will see.” One of the other pilots responded by pulling the circuit breaker to cancel the overspeed warning.</p><p>One second later, First Officer Gerin said, “Now it is three hundred and fifty yes?”</p><p>Once again, this line has several interpretations. For instance, the final report states that he most likely glanced over at Captain Erdem’s airspeed indicator and read off the erroneous value. It is possible to read the other pilot’s airspeed indication, although on the 757–200 it would have taken some effort due to the size and position of the displays. If one subscribes to the interpretation that Gergin was looking at Erdem’s display when he announced “it began to operate” earlier in the flight, then this would be consistent with the assumption that he was still monitoring the captain’s airspeed indicator. However, if one subscribes to Çetin Birgen’s argument that Gergin improperly switched his air data source to “alternate,” then he could have been reading his <em>own</em> airspeed indication, which would have been the same erroneous value displayed to Captain Erdem. And on top of these two possibilities, I would add a third — that he was simply reciting, from memory, the maximum operating speed of the aircraft, as an explanation for the overspeed warning.</p><p>In the seconds before, after, and during this callout, events built to a startling crescendo. As you hopefully recall, the autopilot had been slowly increasing the pitch in an attempt to reduce the erroneously high airspeed. Eventually the pitch attitude reached a maximum value of 15.1˚, where it remained for a considerable period of time. It’s not entirely clear if this was the maximum pitch attitude that could be commanded in VNAV/FLCH, but that would be my assumption. But this pitch attitude was too high for the thrust setting and configuration, which is why their actual airspeed had been slowly decreasing. And as their airspeed decreased, their rate of climb also decreased, even though the pitch attitude wasn’t changing.</p><p>At 23:45 and 47 seconds, Captain Erdem declared, “Let’s take that like this,” and then a confusing series of events happened within a very short time. First, he apparently switched the vertical autopilot mode from VNAV/FLCH to vertical speed (V/S), in which the autopilot pitches up or down to maintain a climb or descent rate selected by the crew. Switching to V/S mode also causes the autothrottle to enter speed mode (SPD), in which it modifies engine thrust to achieve a target airspeed. I’m not an authority on Boeing 757 autoflight systems, but as far as I can tell, switching to V/S and SPD mode from VNAV after retracting the flaps during climb will result in a default target airspeed of 250 knots until the pilots select something else. And because the №1 indicated airspeed was at that moment close to 350 knots, the autothrottle apparently decreased thrust in both engines to idle in order to lose what it believed was an excess of 100 knots’ airspeed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MqQRXspOTf-gim9ym9yZ_A.png" /><figcaption>My understanding of how the autoflight system will operate when switching from VNAV to V/S at flight 301’s altitude and configuration. (Own work, text from the Boeing 757 FCOM)</figcaption></figure><p>At the same time, the flight data shows that after V/S mode was selected, the rate of climb increased from 1,344 feet per minute at 23:45:46 to 1,600 feet per minute at 23:45:52, while the pitch increased from 15 degrees to 18 degrees nose up. In my opinion, this suggests that the target vertical speed was above the actual vertical speed, which caused the autopilot to pitch the nose up even further in an attempt to climb faster. The exact vertical speed that was selected is not stated in the report or included in the flight data, nor do I know whether that target value was selected by the pilot or entered by default from the flight management computer.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XbYwmbB6vB9vdzSsBQF0lA.png" /><figcaption>How the flight data reveals what happened during the crucial moments before the pilots lost control. (AIB Dominican Republic, annotations mine)</figcaption></figure><p>The final report states that during these crucial six seconds, “the flight crew reduced power and increased elevator deflection.” However, in my opinion, the flight data clearly shows that this was not the case. Up until 23:45:52, the autopilot and autothrottle were both engaged, and the increase in elevator deflection (thus pitch angle) and decrease in engine power appear to be consistent with the expected autoflight system behavior given a switch from VNAV to V/S mode at this phase of flight. Therefore, I don’t think the evidence supports a conclusion that these inputs were made by the flight crew.</p><p>Another question not answered by the final report is why Captain Erdem selected V/S mode in the first place. None of his comments on the CVR provide a clear explanation. However, the simplest assumption is that he saw that their rate of climb was decreasing below the value he would expect at this phase of flight, so he selected a mode in which he would have more control over their vertical speed. It has also been suggested that he wanted to increase the vertical speed in order to reduce airspeed in response to the overspeed warning, but in my opinion the evidence indicates that he recognized the overspeed warning as erroneous.</p><p>In any case, the sudden pitch up and decrease in thrust at a moment when the real airspeed was already below normal for this phase of flight resulted in an immediate and dramatic exit from the normal flight envelope. At 23:45:52, the stick shaker activated, vibrating the pilots’ control columns to warn of an impending stall. The aircraft was on an upward trajectory that was completely unsustainable with the current airspeed and thrust, and unless the pilots increased airspeed right away, they were going to fall from the sky.</p><p>In 1996, pilots were taught react to the stick shaker by following “approach to stall” procedures. The idea was that a stall could be avoided by increasing engine power and maintaining a reasonable pitch angle, provided that these steps were accomplished sufficiently far in advance of the stall actually taking place. “Approach to stall” training tended to focus heavily on thrust and emphasized minimizing altitude loss. But these procedures were not adequately aggressive to handle the situation that flight 301 had encountered.</p><p>Captain Erdem was probably caught off guard by the airplane’s reaction to the mode change, but the flight data shows that he began to increase engine power within one second of the stick shaker activation, exactly as he had been trained. This action also disconnected the autothrottle, but the autopilot remained engaged in vertical speed mode, where it kept trying to pitch up to achieve the selected climb rate.</p><p>The final report provides almost no useful information about the behavior of the autopilot during the period between the stall warning and its disconnection, which occurred 6 seconds later at 23:45:58. To make matters worse, the only publicly available FDR readout is missing the crucial page containing the pitch angle, elevator deflection, and stabilizer deflection data between 23:45:45 and 23:46:23. However, it is possible to say that the stabilizer setting was at 6 units at 23:45:45, just before V/S mode was engaged, and by 23:46:23 it had increased to 10 units.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1Z44vtx41830bpsU_tWUbg.png" /><figcaption>How the missing data complicates my analysis of the role of the trim setting. (AIB Dominican Republic, annotations mine)</figcaption></figure><p>The purpose of the horizontal stabilizer is to adjust the aircraft’s natural or stable pitch-speed combination. A higher setting will cause the aircraft to stabilize at a higher pitch angle and lower airspeed, while a lower setting will stabilize the aircraft at a lower pitch angle and higher airspeed. So we simply cannot ignore the fact that the stabilizer setting increased from 6 units to 10 during the period of the stall, precisely when the pilots needed to reduce pitch and increase airspeed. However, the accident report perplexingly makes no mention of this information at all.</p><p>When the autopilot is engaged, the stabilizer position is controlled automatically in order to stabilize the aircraft in the pitch-speed combination required to achieve the target aircraft state. Therefore, during the 13 seconds that V/S mode was active, it should have continuously increased the stabilizer position to try to stabilize the aircraft at a lower airspeed, because the indicated airspeed was very high. However, my understanding is that the rate of automatic stabilizer motion is quite slow, so it’s doubtful that 13 seconds is long enough to explain a deflection of 4 units. Çetin Birgen explained this discrepancy by suggesting that the autopilot had not properly disengaged due to a system fault, but there is no evidence of this, and the flight data clearly shows that the autopilot disconnected at 23:45:58 and was never engaged again. So, without knowing the exact timeframe during which the stabilizer movement occurred, or what the automatic stabilizer deflection rate is, it remains possible that some or even most of the change from 6 units to 10 units was the result of pilot action during the ensuing chaos.</p><iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FSjYzv-nXQKo%3Ffeature%3Doembed&amp;display_name=YouTube&amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DSjYzv-nXQKo&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FSjYzv-nXQKo%2Fhqdefault.jpg&amp;type=text%2Fhtml&amp;schema=youtube" width="854" height="480" frameborder="0" scrolling="no"><a href="https://medium.com/media/21157234b3ada50aa38243886b77a269/href">https://medium.com/media/21157234b3ada50aa38243886b77a269/href</a></iframe><p>Right at the moment that the stick shaker activated, flight 301’s altitude peaked at 7,264 feet before entering a shallow but steepening descent, wallowing along with its nose high in the air. The pitch attitude peaked at 21 degrees nose up right before the autopilot disconnected. The reason why the autopilot disconnected is not stated in the final report, but it could have been done manually by one of the pilots, or automatically in response to some kind of limitation exceedance.</p><p>In the cockpit, the captain and first officer both repeated the word “God” several times, while multiple alert tones chimed against the clack-clack-clack of the stick shaker. Both pilots seemed utterly paralyzed, overwhelmed by the confusing sequence of indications.</p><p>Despite the evident failure of his thrust increase to silence the stick shaker, Captain Erdem took no further action to prevent a stall. It’s quite possible that he believed the stick shaker was erroneous, much like the overspeed warning — but it wasn’t. Although stalls are often discussed with regard to the airspeed at which they occur in a given configuration, the only parameter that determines the point at which an aircraft will stall is its angle of attack, the angle of its lifting surfaces relative to the oncoming airflow. If this angle is too steep, the air will cease to flow smoothly over the wings and the aircraft will stop flying, no matter its speed. For this reason, stall warnings are generated by the angle of attack sensors, with no input from the airspeed sensors at all. That means that even in the absence of any valid airspeed indications, the stick shaker remains trustworthy. It’s not clear that the pilots of flight 301 understood this.</p><p>In the absence of any effort to avert it, the aircraft stalled. Now the only way out was to pitch steeply nose down, putting the airplane into a dive in order to restore airflow over the wings. The pilots would have known in theory that this was the way to recover, but putting it into practice was another matter entirely, especially when they were unsure of the stick shaker’s provenance.</p><p>From the jumpseat, Relief Captain Evrenesoglu possibly realized that the aircraft was in a stall and called out, “ADI” — attitude direction indicator — referring to the pilots’ pitch and roll displays. If this was a call for the pilots to pitch down, it was not straightforward enough to convey the message, and Erdem did not react. First Officer Gergin did shout, “Nose down!” then recited the Islamic phrase <em>bi-smi llahi r-rahmani r-rahim — </em>“In the name of God, the Most Gracious, the Most Merciful.” No sooner had those words left his lips than he again exclaimed, “Thrust!”</p><p>“Disconnect the autopilot, is the autopilot disconnected?” Captain Erdem asked. It’s possible that he was having difficulty controlling the plane in a stalled condition and had begun to wonder whether he was fighting the autopilot. Alternatively, he might have been trying to push down, only to encounter resistance due to the nose up stabilizer setting.</p><p>“Already disconnected, disconnected sir,” Gergin replied.</p><p>“ADI!” Evrenesoglu called out again.</p><p>At around this time, someone pulled back the thrust levers to idle, making the problem even worse. It is unknown who did this or why.</p><p>Over the radio, the Santo Domingo controller asked them to set a new transponder code, but Gergin simply told him to standby. This would be the last anyone heard from flight 301.</p><p>“Not climb? What am I to do?” Erdem exclaimed.</p><p>“You may level off altitude okay, I am selecting the altitude hold sir,” Gergin replied. He then pushed the “altitude hold” button on the autoflight panel. With the autopilot disengaged, the only effect of this action was to instruct the flight director, an overlay on the pilots’ primary displays, to indicate the flight control inputs required to hold their current altitude. This was not in any way useful because the airplane was in a stalled state from which recovery was only possible by trading altitude for speed.</p><p>“Okay, five thousand feet,” Gergin called out, watching their altitude tick steadily downward.</p><p>“Thrust levers, thrust, thrust, thrust, thrust!” Erdem shouted.</p><p>“Retard?” Gergin asked.</p><p>Reducing (“retarding”) engine thrust was not what Erdem wanted. “Thrust, don’t pull back, don’t pull back, don’t pull back, don’t pull back!” he yelled.</p><p>“Okay, open, open,” Gergin said, referring to “opening” the throttles.</p><p>“Don’t pull back, please don’t pull back!” Erdem repeated.</p><p>“Open sir, open!” Gergin said. “<em>Bi-smi llahi r-rahmani r-rahim!”</em></p><p>Gergin pushed the thrust levers forward, but by this point the angle of attack was so high that the airflow into the engine inlets had become highly oblique. In fact, the airflow into the left engine was insufficient to achieve the requested thrust, resulting in a compressor surge as compressed air inside the engine burst forward violently. This caused the left engine’s power output to drop dramatically, while the right engine spooled up as commanded.</p><p>With the aircraft already in a stalled state — essentially falling toward the ground — the sudden application of differential thrust caused it to enter a spin about its vertical axis. The airplane pitched over to a maximum nose down attitude of -53 degrees while simultaneously performing a full 360-degree left roll. From that point onward, recovery was impossible, and the fate of flight 301 was sealed.</p><p>In the cockpit, confusion surrendered to fear.</p><p>“Pull up!” Evrenesoglu shouted.</p><p>“What’s happening?” Erdem exclaimed.</p><p>“Oh, what’s happening?” Gergin repeated.</p><p>The ground proximity warning system roared to life, calling out, “SINK RATE! WHOOP WHOOP, PULL UP!”</p><p>The pilots attempted to pull out of the spin, raising the nose as high as -9 degrees, but the airplane was completely out of control. The Atlantic was rising up beneath them; they were out of time. Still locked in a hopeless spiral, the mighty 757 breathed its last.</p><p>In the cockpit, First Officer Gergin calmly stated, “Let’s do like this” — the final words on the cockpit voice recorder. Four seconds later, pitched 34 degrees nose down and banked 35 degrees to the left, Birgenair flight 301 slammed into the dark waters of the Atlantic Ocean, instantly killing all 189 people on board.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/960/0*nV1Zoe7qPnsTrwLr.jpg" /><figcaption>A rescue boat surrounded by floating debris from Birgenair flight 301. (Stern.de)</figcaption></figure><p>After flight 301 disappeared from radar in Santo Domingo, a search and rescue effort was initiated. Within hours, search vessels located floating debris and bodies in the ocean approximately 23 kilometers northeast of Gregorio Luperón International Airport, strewn across the sea in a grim testament to the violence of the impact. Few of the bodies were intact, and the rescuers described finding coffee cans from the galley that had been crushed into disks by the immense forces.</p><p>Immediately after the accident, an investigation was organized under the leadership of the Dominican Republic’s <em>Junta Investigadora de Accidentes Aéreos</em> (Air Accident Investigation Board), or JIAA. In accordance with international law, representatives of the United States National Transportation Safety Board were invited on behalf of the state of manufacture of the aircraft, while the Turkish Directorate General of Civil Aviation was invited on behalf of the aircraft’s state of registry. The US and Turkish investigators were accompanied by representatives of Boeing and Birgenair, respectively.</p><p>A specialized salvage ship was commissioned from the United States to locate and recover the flight recorders. Arriving on the scene early in the morning on the 28th of February, the vessel’s sonar equipment detected the battery-powered pingers from the flight recorders within two hours of searching, and both boxes were successfully recovered that same day from a depth of 7,200 feet (2,190 m).</p><p>After the contents were downloaded, it quickly became clear that the flight data recorder had captured erroneous airspeed data throughout the flight. The 757’s FDR draws its airspeed data from the captain’s pitot tube only. This data showed the airspeed increasing to a peak of 353 knots shortly before the aircraft reached its maximum altitude, despite a pitch angle and thrust setting that would not have permitted such a high airspeed. In fact, these data were consistent with a pitot tube that was completely blocked, causing it to measure an airspeed proportional to altitude.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8NrhRbEzA_gGQUQxP5K7wg.png" /><figcaption>Tires from Birgenair flight 301 aboard a salvage ship after the accident. (Unknown author, possibly Dominican Republic AIB)</figcaption></figure><p>Very little wreckage was retrieved from the seabed, and the pitot tubes were neither observed nor recovered, so there was no way to conclusively determine the nature of the hypothetical obstruction. However, ice could be ruled out due to the balmy temperatures in Puerto Plata. A pitot tube cover left in place could affect airspeed readings, but maintenance crews testified that covers were not used, and a cover would have been obvious during the pre-flight inspection. In light of the fact that covers were not installed for at least two days prior to the flight, and the fact that <em>Sceliphron caementarium </em>is native to the area and is known to build nests inside pitot tubes, investigators concluded that the most likely explanation was that wasps had stuffed the tube full of mud.</p><p>Çetin Birgen disputed this explanation. In his own submission, he argued that there had been “numerous cases where rainwater had entered the pitot tube and had affected the operation of the connected systems.” He did not cite any examples, nor did he explain how rainwater, which should be flushed out as soon as the aircraft accelerates, could trap sea level air inside the pitot tube in such a way as to produce the recorded data.</p><p>How exactly this bad data led to the loss of 189 lives is also a matter of some dispute. In fact, throughout this article, I’ve presented competing interpretations of the pilots’ statements and actions, so you should be already familiar with the substance of most of the arguments. But it’s also worth examining why there’s so little consensus about the exact sequence of events.</p><p>Unfortunately, the final report produced by the Dominican JIAA is among the worst I’ve ever read. It is unacceptably short, lacks crucial details, and contains numerous factual errors, ranging from the age of the captain to the exact timing of the autopilot disconnection. Its analysis of the events is sometimes unsupported by the raw data, and some parts are based on apparently misattributed statements from the cockpit voice recorder. It does not appear that the investigation conducted any tests to better understand the autopilot behavior or to place the pilots’ statements into the context of what they were seeing.</p><p>The NTSB, the Turkish DGCA, Boeing, and Birgenair all wrote responses to the accident report. The NTSB and Boeing responses simply clarified a few points and requested some minor changes, while the Turkish DGCA questioned just a couple of the core findings. By contrast, Çetin Birgen’s bombastic response on behalf of his airline questioned practically everything that the JIAA wrote, including the very basis of the agency’s jurisdiction over the case. In fact, he argued that the aircraft had crashed in international waters and that in the absence of a valid “state of occurrence,” the investigation should have been led by Turkey as the “state of registration,” effectively accusing the JIAA of seizing control of the investigation without regard for international law. However, his position seems to be based on a fundamentally flawed and carelessly researched application of the definition of “international waters.” Under international law, “international waters” begin 12 nautical miles offshore, and indeed flight 301 crashed about 12.5 nautical miles <em>away from the airport</em>, but the crash site is actually only about 8 nautical miles from the nearest point on land, placing it firmly inside the territorial waters of the Dominican Republic.</p><p>Not all of Birgen’s arguments were as bad as this one, and some of them I actually agree with — but only when verified by the raw flight data and cockpit voice recorder transcript. Fortunately, those documents are publicly available and I relied heavily on them to tell this story. What follows now is my evaluation of the arguments made by all parties about the fundamental causes of the accident, and especially those made by the JIAA and Çetin Birgen, in light of the available hard evidence and developments in aviation safety over the last 30 years.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*j6gyodQ3b0EINu35hakekw.png" /><figcaption>The tail section was found in one main piece, lying inverted on the seabed. (Unknown author, possibly Dominican Republic AIB)</figcaption></figure><p>In its own analysis, the JIAA argued that the pilots initially identified the faulty airspeed indicator, but failed to appropriately reject the takeoff. They were subsequently reassured that all was normal when the captain’s indicated airspeed started increasing through a range of reasonable values. The pilots then attempted to continue a normal climb, without recognizing that the autopilot was steadily pitching up. When additional abnormal indications started to appear, including the “rudder ratio” and “mach/speed trim” EICAS messages, the pilots became confused about the actual nature of the problem. The first officer accurately determined that their airspeed was decreasing, and the captain accurately observed that the standby airspeed indicator was correct, but nobody attempted to unite these observations into a plan of action. They should have carefully determined which airspeed indicators were trustworthy, handed control to the first officer, and assumed a safe pitch attitude and thrust setting, but they didn’t. Instead, they tried to troubleshoot, searching for the cause of the disparate indications before trapping their consequences. Having failed to accomplish this, they were unprepared for the false overspeed warning. Despite telling the first officer to ignore the warning, Captain Erdem hesitated to practice what he preached, and began to decrease engine thrust and pitch up, which sent the aircraft into a stall. The crew failed to recognize that the stick shaker was providing an accurate warning of the impending stall, and they did not execute the stall recovery procedures. Disjointed and irrelevant inputs made the loss of control worse, until recovery became impossible.</p><p>As reasons for this chaotic behavior, the JIAA cited a lack of training. Birgenair’s flight crews did not receive crew resource management (CRM) training, which was not required in Turkey at the time. This training would have helped them take advantage of all three pilots’ extensive experience to determine the safest course of action. But perhaps even more significantly, they had not been trained to react to an unreliable airspeed indication. Boeing’s flight crew training manual at the time assumed that pilots could handle such a situation with “little difficulty” by comparing the three airspeed indications and discarding the odd one out. But pilots at most airlines around the world were not actually trained to do this, nor were they given even basic written guidance. In 1995, Birgenair did introduce some simple unreliable airspeed guidance to its flight crew operations manual, which instructed pilots to adopt a known pitch angle and thrust setting to ensure a safe flight path before troubleshooting, but this guidance was not used in training and there is no evidence that the pilots of flight 301 knew of its existence.</p><p>As a result, the pilots did not properly integrate their observations related to the airspeed indications and did not know which warnings were likely to be false and which were likely to be true. Unsure what to do, they became paralyzed by their own confusion and did not react to save the plane.</p><p>This is the story of the accident that is most often told, but as you’ve already gathered by now, I don’t think it accurately reflects the true causes of the crash. The points about training are spot on, but not for the reasons that the JIAA claimed. I’ll go into that in more detail shortly. But first I want to similarly summarize Çetin Birgen’s argument.</p><p>Birgen’s submission was at times conspiratorial and generally worked hard to deflect responsibility from Birgenair. He called the final report “flawed and misleading in many material respects,” which it was, and wrote that it demonstrated an “obvious lack of care in dealing with facts.” But Birgen was throwing rocks in a glass house, because many of his claims were equally dubious, especially his argument that Turkey should have led the investigation, and his argument that Captain Erdem selected his alternate air data source then switched it back, which was based on obviously corrupted data. So, discounting the clearly false parts of his account, what follows is a distilled version of Birgen’s overall argument.</p><p>In his view, the pilots recognized that the captain’s airspeed indicator was faulty from the very beginning and maintained this understanding throughout the flight. They chose not to reject the takeoff because the aircraft had already entered the high speed regime, and a fault with one airspeed indicator did not seem to outweigh the risks of a rejected takeoff. Subsequently, when the first officer said “it has begun to operate,” he meant that LNAV mode was armed. The pilots didn’t understand that the autopilot was using the captain’s false airspeed data because the air data architecture was not sufficiently covered during the pilots’ recurrent training in the United States. The next sign of a problem was the appearance of the “rudder ratio” and “mach/speed trim” EICAS messages, which were unhelpful because the procedures associated with these messages made no mention of the possibility that they could be triggered by a false airspeed reading. But the pilots didn’t even consult those procedures because the messages were marked as advisory only.</p><p>When the overspeed warning sounded, Captain Erdem correctly recognized that the warning must be false because even the overpowered Boeing 757 can’t achieve such a high speed with the engines in climb power and a pitch of 15 degrees nose up. However, at the same time, First Officer Gergin possibly reacted to the call that “alternate is correct” by switching his air data source to alternate, causing him to receive the same false airspeed data as the captain. This error was caused by a lack of understanding of the air data architecture, the details of which were not provided to him during training or in the manual. Without a valid airspeed reading on either display, the flight crew became confused about their actual airspeed. The autopilot kept pitching up until the stall warning sounded. According to the Boeing 757 training manual, the pilot should react to an approach-to-stall with the autopilot engaged by increasing engine power to return the aircraft to a normal airspeed, and if this doesn’t work, disengage the autopilot. Captain Erdem immediately performed these exact actions.</p><p>After the stall began, Birgen argued that the autopilot actually re-engaged due to a “known fault” with the 757’s autopilot system, which could cause the autopilot to re-engage following an automatic disconnection if the pilot didn’t follow up by pressing the autopilot disconnect button. He claimed this fault was known to Boeing and had been observed in the past but provided no examples nor any credible information related to this alleged issue. In his opinion, this could have caused the autopilot to re-engage in altitude hold mode, resulting in pitch-up inputs on the elevator and stabilizer that made it harder for Erdem to recover from the stall. However, the FDR data shows that the autopilot didn’t re-engage at any point, and in the absence of any evidence whatsoever, this argument can easily be dismissed.</p><p>In Birgen’s opinion, the cause of the accident was Boeing’s failure to provide flight crews with the technical information and procedures required to recognize that an unreliable airspeed event was occurring, predict its consequences, and respond in an appropriate manner.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qRlHTXLME26XRFVC4QiXXA.png" /><figcaption>Another view of the intact tail section. (Unknown author, possibly Dominican Republic AIB)</figcaption></figure><p>After weeks spent researching this accident, I came to believe that neither the JIAA nor Çetin Birgen articulated a sequence of events and causal factors that adequately reflects the evidence. I’ve already shared my opinions at various points throughout this article so far, but I will summarize them again here. But once again I must highlight that what follows is fact-based, but is not fact; it is not the product of a professional investigation. It is my personal opinion based on examination of the raw evidence.</p><p>My belief is that Captain Erdem made a judgment call that it was safer to take off than to abort, because the first officer had a valid airspeed reading. A pilot today might not necessarily make the same decision, but at that time a single inoperative airspeed indicator was thought to present “little difficulty” to the flight crew.</p><p>I think Erdem was aware throughout the flight that his own airspeed reading was incorrect, and I think the first officer’s call that “it has begun to operate” either was not referring to the airspeed indicator at all, or did not cause Erdem to believe his airspeed indicator. His actions throughout the flight are inconsistent with someone who believed the airplane was flying at an unreasonably high speed. However, due to an inadequate understanding of the air data architecture and autoflight systems, he did not recognize that the <em>center</em> autopilot would fly the airplane using air data from the <em>left </em>pitot-static system. The pilots did not adequately monitor their pitch attitude, probably because they didn’t expect the autopilot to behave in a deviant manner. The “rudder ratio” and “mach/speed trim” EICAS messages were confusing and might have sowed a lack of trust in the aircraft’s warning systems. This was compounded when First Officer Gergin reported that his airspeed indication was falling below 200 knots, which did not correlate with Erdem’s belief that the autopilot was flying the plane normally. He then concluded that Gergin’s airspeed display must also be incorrect. By this point the situation would have been quite concerning, but with no training on what to do next, Erdem continued to trust that the autopilot would fly the plane in a safe manner while he tried some basic troubleshooting. His call to disregard the overspeed warning was consistent with his understanding that his very high airspeed indication was erroneous.</p><p>Eventually, the increasing pitch angle caused the airplane to bleed off too much speed to maintain the desired climb rate, which became the first indication to Erdem that the autopilot was not behaving normally. Unsure why VNAV was not producing the expected climb rate, he decided to take more direct control of their flight path by engaging V/S mode with a higher climb rate selected. This caused the autopilot and autothrottle to switch from a continuous thrust, speed-on-pitch philosophy to a speed-on-thrust, vertical speed-on-pitch philosophy. Because the indicated airspeed was 350 knots while the probable target airspeed was 250 knots, the autothrottle reduced thrust to idle in order to slow down, while the autopilot increased pitch to its command limit in an attempt to make the aircraft climb faster. This combination of inputs caused the angle of attack to exceed the stick shaker threshold within six seconds.</p><p>After the stick shaker activated, Captain Erdem responded according to his training by increasing engine power. However, he didn’t apply maximum power, he didn’t pitch down, and he didn’t disengage the autopilot. I think at this point he still believed that the autopilot would react appropriately with his help. Six seconds later, the autopilot did disconnect, possibly because Erdem had realized that it was actively trying to stall the airplane. But by then it was too late; the stall had already taken place. Once in a fully developed stall, the only way to escape was to trade altitude for airspeed by pitching down well below the horizon — but pilots in 1996 had no opportunity to practice this. Simulator training focused on preventing stalls by increasing engine power and maintaining a slight nose-up attitude, which is what he did. When this failed to silence the stall warning, he might have concluded that the warning was false, without realizing that the stick shaker operates independent of airspeed.</p><p>After this point, the actions of the crew became chaotic and difficult to explain. I was not able to determine beyond reasonable doubt why the stabilizer setting increased to 10 units, but it probably resulted in control forces that captain Erdem would have found confusing. Someone also decreased thrust to idle for a considerable period of time, which I think might have been done by First Officer Gergin, given that Captain Erdem seemed quite emphatic about his desire that thrust should be increased. None of the pilots recognized that they were in a fully developed stall. Eventually, the left engine suffered a compressor surge, and differential thrust sent the aircraft into a spin from which recovery was impossible.</p><p>In my opinion, the causes of this accident were a lack of systems knowledge, which led to incorrect decision-making, especially with regard to the autoflight systems; and a lack of training and procedures for an unreliable airspeed emergency. The nature of stall training at the time, which didn’t allow pilots to practice recovering from a fully developed stall, also may have contributed.</p><p>The JIAA, Birgen, and I all agree that the failure to cover the pitot tubes while the aircraft was parked contributed to the accident, although Birgen argued that this wasn’t technically required. The JIAA also argued that Captain Erdem’s decision not to abort the takeoff was a contributing factor, but Birgen and I both agree that his decision would have seemed reasonable in the moment. The JIAA and I also agree that the pilots might have been fatigued.</p><p>Overall, I think the case of Birgenair flight 301 vividly illustrates how an unreliable airspeed emergency can quickly overwhelm even a relatively competent flight crew in the absence of clear guidance on what to do. In this case, the pilots had two valid airspeed readings available to them, and if Captain Erdem had simply disengaged the autopilot and handed over control to First Officer Gergin, the rest of the flight probably would have been uneventful. Instead, a single wasp’s nest in a single pitot tube led to a complete loss of control because the pilots didn’t understand that bad data on their instruments could mean the autoflight systems are getting bad data too. As I said earlier in this article, that fact seems self-evident now, but that’s in part because today’s pilots already know stories like this one. And they know these stories because unreliable airspeed events are rigorously drilled in initial and recurrent training — but that wasn’t the case in 1996. The crash of Birgenair flight 301 intensified calls for such training, but it would take another accident for those voices to reach their crescendo.</p><p>◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/731/0*iIQrq4Yzl13EZnVQ.jpg" /><figcaption>A 1970s-era advertisement for Aeroperú. (Airline memorabilia)</figcaption></figure><h3><strong>Part 2: Panic in Peru</strong></h3><p>Founded in 1973, Aeroperú was the flag carrier of its namesake nation for 26 years until its bankruptcy in 1999. The airline was initially state-owned before undergoing gradual privatization starting in 1981, which culminated in the purchase of a controlling stake by Mexican flag carrier Aeroméxico in 1993. By 1996, its fleet included McDonnell Douglas DC-10s, Fokker F-28s, Boeing 727s, and of course several Boeing 757–200s, the same model involved in the crash of Birgenair flight 301.</p><p>The Boeing 757 at the center of this story bore the United States registration N52AW, although it was owned and operated by Aeroperú. I wasn’t able to determine why the aircraft was registered in the US, but everything else about its operation appears to have been normal, unlike the sketchy origins of Birgenair.</p><p>Although Aeroperú outsourced heavy maintenance of its 757s to parent company Aeroméxico, regular line maintenance and repairs were accomplished in-house at Jorge Chávez International Airport in Lima. That was where N52AW found itself on the 1st of October 1996 after suffering a bird strike into its right engine.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*yQmrT2Xxfy07thY9.png" /><figcaption>N52AW, the aircraft involved in the accident. (Torsten Maiwald)</figcaption></figure><p>Although the damage from this incident was relatively minor, it did require technicians to replace two fan blades and repair the engine hydraulic pump. But that’s not key to this story — what is key is that the work also involved polishing the underside of the forward fuselage. The final report doesn’t say whether this was to clear dust and debris left by the maintenance work, or to clean off bird viscera, but my imagination tends to pull me toward the latter.</p><p>The underside of the forward fuselage happens to contain the static ports for all three pitot-static systems, which could be contaminated if left open during cleaning. For this reason, some airlines have special covers that can be placed over the static ports, but Aeroperú lacked anything of the sort. Instead, Aeroperú technicians decided to cover the static ports with silver aviation-grade masking tape. As far as I’m aware, this isn’t inherently unsafe, so long it’s removed again before flight. But as it turns out, that’s a huge caveat that greatly affects the overall wisdom of the decision.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/300/1*rTJM6AqJbO1aNworhfJlSA.jpeg" /><figcaption>The general appearance of the Boeing 757’s static ports. (FAA)</figcaption></figure><p>The problem with this tape was that it was almost the same color as the lower fuselage itself, which was silvery-gray in Aeroperú’s livery. Due to this color similarity, the tape was difficult to spot during a cursory inspection unless the technicians explicitly divulged that they had put it there. But in this case, a breakdown of communication occurred. Details are scarce, but the final report states that the supervisor in charge of the work was replaced at some point due to illness, and the new supervisor then appointed a new mechanic to “attend to the aircraft on the apron.” Neither of these individuals noticed the tape during final inspection of the work. However, the exact roles and expectations of these people are not explained in the report and it remains unclear from that document who was responsible for taking the tape off. One technician was later convicted of negligent homicide as a result of the events, but he was widely considered a scapegoat.</p><p>As you’ve probably guessed, the tape was inadvertently left in place. The final report doesn’t explicitly state that the tape was left on all three sets of static ports, and in fact only the captain’s and first officer’s static ports were found, so the status of the standby system is technically unknown. Updates from the first few months of the official investigation suggest that investigators did not yet know whether all the static ports were covered, but the cockpit voice recorder transcript doesn’t support a conclusion that they had accurate pitot-static information. In fact, the transcript clearly suggests the opposite. This isn’t particularly surprising, because if mechanics had removed the tape from one set of static ports, it’s difficult to understand why they would not remove the tape from the rest of the ports too. So my assumption going into this story is that all the static ports were taped over.</p><p>Later that night, the aircraft was released from maintenance to perform the scheduled flight 603 from Lima to Santiago, Chile. This red-eye flight was lightly booked, with just 61 passengers scattered throughout the 757. Nine crewmembers were also rostered, including two flight crew.</p><p>The captain was 58-year-old Eric Schreiber Ladrón de Guevara, a highly experienced pilot with nearly 22,000 flying hours, including over 1,500 on the Boeing 757. The first officer was 42-year-old David Fernández Revoredo, who was also fairly experienced, with almost 8,000 total hours, including 719 hours on the 757. The final report doesn’t include detailed information about their career backgrounds or type rating histories.</p><p>After arriving at the aircraft sometime around midnight, Captain Schreiber conducted a routine walkaround inspection, searching for anything out of the ordinary. But on the poorly lit apron, the silver tape against the silver fuselage was very difficult to see, positioned as it was above Schreiber’s head height. That being said, the thoroughness of his walkaround inspection is unknown; all that can be said with confidence is that he didn’t see the tape.</p><p>The effect of tape over the static ports is not the same as the effect of a blocked pitot tube, nor is it particularly intuitive. Because tape is somewhat porous, a small amount of air will leak through the tape, but at a very reduced rate. Before takeoff, the pocket of air trapped inside the port would be pressurized to sea level, but as the aircraft climbs, this pocket will slowly depressurize until it eventually equalizes with the lower ambient pressure at altitude. Then, if the aircraft descends, the air will take an equal amount of time to leak back through the other way. The effect is to create a lag of several minutes in the measured static pressure.</p><p>This “lag” will result in an altitude reading that is too low when climbing, becomes accurate after a period of level flight, then becomes too high when descending. And because airspeed is calculated based on the difference between pitot pressure and static pressure, the erroneously high static pressure during climb will cause the airspeed to read too low, and the erroneously low static pressure during descent will cause the airspeed to read too high. This makes the false indications significantly more complicated than in the case of a single blocked pitot tube, where airspeed increases proportionally with altitude. This is especially true if all the static ports are blocked, as they most likely were in this case, not only because all three altitude and airspeed readouts will be wrong, but also because they might be wrong in different ways, due to differences in the speed of air leakage through each strip of tape.</p><p>In this case, the usual tactic of comparing the three indications and eliminating the odd one out will be ineffective. Instead, the solution is to evaluate the reasonableness of each indication with respect to the pitch attitude and thrust setting. If all three airspeed indications are unreasonable, then the pilot can still approximate their speed by referring to the ground speed indicators, which are independent of the pitot-static system but don’t account for wind. Height above the ground can also be determined by using the radio altimeter, which on the 757 is functional below 2,500 feet and is independent of the pitot-static system. Above that height, it may not be possible to reliably determine the aircraft’s altitude.</p><p>Everything I just said is included in basic unreliable airspeed training today. However, as I said in Part 1, that training did not yet exist in 1996 outside of a few airlines at the forefront of safety. Neither pilot on Aeroperú flight 603 had received such training, nor had they received any guidance on what a blocked pitot tube or static port might look like. No unreliable airspeed procedure existed in the quick reference handbook.</p><p>Both before and after the Birgenair accident, several US airlines began developing FAA-approved emergency procedures for unreliable airspeed events, but these procedures were not added to Boeing’s official 757 manuals, nor were they shared with other airlines around the world. The Birgenair crash prompted the US NTSB to write a letter urging the FAA and Boeing to make several changes, including updating the 757 flight manual to indicate that the appearance of the “rudder ratio” and “mach/speed trim” messages could indicate unreliable airspeed; developing a computerized cross-check that can warn the pilots if the airspeed is unreliable; developing and distributing an official emergency procedure for an unreliable airspeed event; and requiring unreliable airspeed scenarios during training. However, by October 1996 none of these measures had been implemented, nor was anyone at Aeroperú aware that the recommendations had even been issued.</p><p>This type of communication failure has become much less common with the advent of the internet, which has provided a platform for companies and pilots to actively seek out official information about contemporary accidents. By contrast, in 1996 most pilots still relied on their employers to distribute this information through print publications. Therefore, because Aeroperú had not distributed the interim recommendations, it’s unlikely that the pilots of flight 603 knew much about the still-ongoing investigation into Birgenair flight 301 beyond whatever was reported in the Peruvian media.</p><p>◊◊◊</p><p>At 00:41 local time, now on the 2nd of October, Aeroperú flight 603 lined up on Lima’s runway 15 and received clearance for takeoff. The weather conditions were ideal, with a single cloud layer between 900 and 3,100 feet, and only 3 knots of wind. With First Officer Fernández at the controls and Captain Schreiber monitoring the instruments, the pilots set takeoff thrust, and the 757 sped away down the runway. Because the static pressure was correctly reading sea level, everything appeared normal, and the airspeed indicators dutifully reported their actual airspeed. Captain Schreiber called out 80 knots, then V1, and finally “rotate,” prompting Fernández to lift the aircraft off the runway. Schreiber then announced “positive rate,” and Férnandez ordered “gear up.”</p><p>A few seconds later, immediately after raising the gear, Schreiber noticed that something was amiss. “The altimeters are stuck,” he said, noting that his altimeter was reading near zero, and presumably both others were, too.</p><p>Two seconds later, an electronic voice called out, “WINDSHEAR! WINDSHEAR!”</p><p>This warning was generated by the reactive windshear warning system, which monitors aircraft performance in order to detect sudden changes in wind speed and direction (windshear) that may be affecting the flight path. In this case, because the vertical speed was zero with the aircraft at full takeoff thrust and a nose-up pitch, the windshear computer interpreted this set of readings as evidence that the aircraft was encountering a severe downdraft.</p><p>Neither pilot commented on the warnings, which were clearly false given that the tower was reporting negligible wind, nor was there any real weather activity in the airport vicinity at all. Instead, Captain Schreiber again called out, “Hey, altimeters have stuck!”</p><p>“Yeah,” said Férnandez, glancing around the cockpit. “All of them.” At an altitude of just 300 feet, he leveled off momentarily, unsure how to proceed with no altitude readouts.</p><p>“This is really new,” Schreiber drily commented. “Keep V2 plus ten, V2 plus ten.” Keeping a consistent known airspeed would help ensure that the aircraft remained on a safe trajectory as it moved out over the Pacific Ocean. Fernández acknowledged, and the aircraft began to climb again, vanishing from sight into the bottom of the cloud layer. Neither pilot realized that as they climbed higher, their airspeed would read further and further below the actual value.</p><p>For some time, the pilots expressed confusion about their airspeed readings. From the contents of their conversations, it’s possible that Fernández was unable to keep the indicated airspeed above V2 plus ten knots without pitching forward, causing Captain Schreiber to call for 10 degrees pitch. This was a reasonable course of action consistent with guidance for an unreliable airspeed event.</p><p>Into the middle of this confusion, the “rudder ratio” and “mach/speed trim” messages appeared as a result of the increasing divergence between the various airspeed readings, exactly like on Birgenair flight 301. Captain Schreiber read these messages aloud but didn’t appear to understand what they meant. Férnandez then attempted to engage the center autopilot, but it wouldn’t connect.</p><p>While Schreiber tried to figure out the meaning of the “rudder ratio” messages, Fernández attempted to switch his air data source to “alternate,” but this made no difference because all data sources were erroneous. “Let’s go back to basic instruments, everything has gone shit,” he said. He then keyed his microphone and reported, “Tower, Aeroperú 603, we are in an emergency… we have no basic instruments, no altimeter, no speedometer, we declare an emergency!”</p><p>By now, the altitude readout had started to creep upward as pressurized air in the static ports leaked through the tape — but each altimeter was showing something different. Amid the resulting confusion, both pilots cursed the mechanics who had worked on the plane — “What shit have they done!?” Schreiber exclaimed.</p><p>At 00:45, Fernández began requesting vectors for an approach back to Jorge Chávez, but Schreiber told him “Not yet, not yet, let’s stabilize.” He began to read from the quick reference handbook section on the “rudder ratio” caution, while Fernández acknowledged the controller’s instructions to turn right onto heading 330 and maintain present altitude. But what altitude was that? Fernández’s altimeter was showing 4,000 feet, but it didn’t stop increasing when he tried to level off. “What level do we have, do we have 4,000 feet?” he transmitted, hoping that the Lima departure controller could verify their altitude using radar.</p><p>Unfortunately, what seemed like a good idea on paper was actually a major mistake based on an incorrect understanding of both the 757’s air data architecture and the capabilities of ATC radar. In fact, controller’s secondary radar doesn’t independently determine an aircraft’s altitude; instead, it simply displays the barometric altitude transmitted by the plane’s own transponder, which comes from the pitot-static system. So as it turns out, the controller was seeing the same wrong altitude readout that the pilots were — and by verifying that the readouts were the same, he inadvertently encouraged the pilots to trust an instrument that was providing false information.</p><p>For several minutes, the pilots continued their futile struggle to understand what the aircraft was doing, repeatedly expressing their frustration without zeroing in on a course of action. They were unable to determine why the rudder ratio caution had appeared, which disproportionately occupied their attention. Throughout this time, they continued to fly to the southwest over the ocean instead of turning north toward the heading provided by ATC, apparently because they wanted to get as far away from terrain as possible.</p><p>With the altimeters now indicating nearly 10,000 feet, they debated what altitude to level off at, without being entirely sure what altitude they were really at. They also realized that they had forgotten to retract the flaps after takeoff, which they now did. For some time they argued about whether the autopilot was on or off. Eventually they appeared to level off at 12,000 feet, but their actual altitude is uncertain and was probably fluctuating, with an estimated peak around 13,000 feet. The pilots continued to observe that their airspeed was unreasonable for the current thrust and pitch, prompting them to switch the air data source again, but this made no difference.</p><p>Finally, the crew decided to fly the instructed heading 330 in an effort to intercept the landing course. This heading took them outbound parallel to the extended centerline of runway 15. ATC later modified their suggested course to 360, or due north. After confirming that the crew were able to read the Lima VOR radio beacon, the controller then instructed them to cross radial 315 of the VOR, then turn to intercept the landing course and descend to 4,000 feet, in the event of a loss of communication.</p><p>In the cockpit, the pilots struggled to understand their airspeed readouts amid multiple changes in engine power. Eventually, Fernández again gave up and asked air traffic control to help read out their speed and altitude, which was moderately helpful because the controller did have access to their ground speed — but of course, so did the pilots.</p><p>In the meantime, Fernández attempted to initiate a descent, but even with the engines at idle, their airspeed continued to increase. (Remember what a blocked static port does to the airspeed during descent?) “We have all engines cut and it’s accelerating… accelerating!” Fernández exclaimed. He extended the speed brakes in a further attempt to slow down, but this seemingly had no effect.</p><p>Seconds later, the overspeed alarm sounded, triggered by the erroneously high airspeed readings. “What would be the real speed?” Schreiber asked.</p><p>“This one is okay,” said Fernández. “They are okay, the speed… airspeed…”</p><p>“But with all power cut down, it can’t be, with all power cut down… there’s a problem with the source instrument,” Schreiber reasoned. The pilots again messed with the air data source selector, to no avail. Schreiber then began trying to work out what inputs would get them where they needed to go with no airspeed readout: “Let’s see, how many miles… at 30 miles from Lima, we start descending with spoilers and flight level change…”</p><p>“You are crossing the 260 [radial] of Lima, at 31 miles west,” ATC reported. “Flight level is 10,700, and approximate speed is 280 [knots] over the ground.” Once again, the altitude was false, but the ground speed was correct.</p><p>“Yeah but we have an indication of 350 knots here,” Fernández replied, recognizing that their airspeed and ground speed were much too far apart to be realistic.</p><p>Moments later, the overspeed alarm sounded again. “Fucking shit! I have speed brakes!” Fernández shouted in exasperation. “Everything has gone, all instruments went to shit, everything has gone, all of them!”</p><p>As if to punctuate his confusion, the stall warning suddenly activated, and the heavy clack of the stick shaker broke through the high-pitched rattle of the overspeed warning. Incredibly, the airplane was telling them that they were flying too fast and too slow at the same time. The confusion this must have caused is difficult to fathom. But once again, the overspeed warning was false, while the stall warning — derived from the angle of attack sensors, not the pitot-static system — was very much real. By reducing engine power and extending the speed brakes, Fernández had caused the airplane to bleed away speed extremely quickly, causing the angle of attack to increase in order to maintain lift, and now the angle of attack was approaching the critical point. Any higher and the wings would cease to generate lift, and the airplane would fall from the sky.</p><p>“We are going down!” Fernández exclaimed. “I don’t think so… it can’t be overspeed.” He managed to arrest the loss of speed just before the aircraft actually stalled, preventing a catastrophic situation from developing, but the stick shaker continued to activate intermittently.</p><p>At this point, Fernández had a novel idea: what if they flew in formation with another aircraft, allowing them to match its speed and altitude, like following a pace car in motorsport? Calling ATC, he asked, “Is there any aircraft that can take off to rescue us?”</p><p>Schreiber was apparently taken aback by the idea. “Er… wait, no, no no, no,” he exclaimed.</p><p>“Any plane that can guide us, an Aeroperú that may be around? Somebody?” Fernández continued.</p><p>“Don’t tell him anything about that!” Schreiber admonished.</p><p>“Yes, because right now we are stalling,” said Fernández.</p><p>“Attention, we have a 707 that will depart to Pudahuel [Santiago Airport], we are telling him,” said the controller.</p><p>“We are not stalling! It’s fictitious, it’s fictitious!” Schreiber insisted. Much like the Birgenair pilots before him, he didn’t understand that the stall warning remains valid even if all pitot-static data is lost.</p><p>“No! If we have stick shaker how would it be not?” Fernández argued.</p><p>“Shaker… but it is… but even with speed brakes on we are maintaining 9,500,” Schreiber said, sounding confused. Indeed, their altimeters were still reading 9,500 feet, despite the fact that the aircraft was descending. “Why do we read the same? I don’t understand… power. What power do we have?” he asked.</p><p>Fernández read a value of 395 knots off his airspeed indicator; the overspeed warning was still rattling away in the background.</p><p>“Aeroperú 603, you have turned slightly to the left, now you are heading 320 and your level is 100 [10,000 ft], approximate speed of 220 knots and a distance of 32 miles northwest of Lima,” the controller transmitted.</p><p>The pilots reacted again with confusion. They had been trying to descend for approach, why were they still at 10,000 feet? That didn’t seem possible. Fernández started frantically searching for a switch to silence the overspeed warning, although the only way to do this is by pulling the circuit breaker.</p><p>“Nine thousand feet if it indicates you… it’s fictitious, everything is fictitious, all the pitot has gone, the air data has gone to shit,” Schreiber exclaimed.</p><p>By now, Aeroperú maintenance was in contact with ATC, having been made aware of the ongoing situation. On behalf of maintenance, the controller asked flight 603 if their flight computers were working, and Fernández simply replied that all their instruments were wrong.</p><p>At 01:02–20 minutes after takeoff — ATC reported, “The 707 will be ready in some 15 minutes to fly west and help you.” But at this rate, staying airborne for 15 more minutes was a tall order.</p><p>Suddenly, the ground proximity warning system roared to life, calling out “TOO LOW, TERRAIN! TOO LOW, TERRAIN!” The warning sounded continuously for the next 45 seconds, repeating no less than 22 times.</p><p>“What’s happening?” Schreiber asked.</p><p>“Too low, terrain,” Fernández repeated.</p><p>“Let’s go left,” Schreiber declared. With the altimeters still showing nearly 10,000 feet, he apparently concluded that they had strayed over land and were approaching Peru’s coastal mountains, which exceed 10,000 feet within 35 nautical miles of the coast. Therefore, his suggestion was to turn left, pointing the plane out to sea and away from the high terrain. But in fact, they were already over the water, and the GPWS sounded because they were descending into the ocean — Schreiber just couldn’t tell, because it was a cloudy night, and the ground was invisible. It must also be noted that the old style GPWS installed on flight 603 was independent of the pitot-static system; it operated using the radio altimeter, and its warnings were valid.</p><p>As if to make matters even more confusing, after a few seconds the GPWS alarm was joined by three “WINDSHEAR!” callouts. This indicates that their actual height above the water was less than 1,500 feet, because the reactive windshear warning is inhibited above that altitude.</p><p>“We have a terrain alarm, we have a terrain alarm!” Fernández reported to the controller.</p><p>“Roger, according to monitor… it indicates flight level one zero zero [10,000 ft] over the sea, heading a northwest course of 300,” the controller replied.</p><p>“We have a terrain alarm and we’re supposed to be at 10,000 feet!?” Fernández said.</p><p>“According to monitor you have 105 [10,500],” the controller repeated. This report reassured the pilots that the terrain alarms were false — but they weren’t.</p><p>“We have all computers crazy here,” Fernández reported.</p><p>“Shit, what the hell have these assholes done,” Schreiber cursed.</p><p>After a back-and-forth exchange with ATC about why they were flying west, they again compared their speed readouts: 370 knots airspeed on the aircraft, 220 knots ground speed on radar.</p><p>“Shit! We will stall now,” Schreiber exclaimed. 220 knots in their configuration was too slow.</p><p>Four times, the GPWS called out “SINK RATE!” as the aircraft suddenly lost altitude. “Let’s go up, let’s see, let’s go up here,” Fernández decided, increasing thrust and pitching up to put the airplane into a climb. This action thankfully saved the plane both from a possible stall and possible ground impact. The overspeed warning continued to sound, while the altimeter continued to indicate above 9,000 feet, leading to another long and confused exchange between the pilots, but eventually they leveled off at a real altitude thought to have been about 4,000 feet.</p><p>With the aircraft now in apparently stable, level flight, despite the overspeed alarm, Schreiber decided that they were now in a position to maneuver for approach. The pilots made a rudimentary attempt to determine which instruments were trustworthy, and concluded that the only thing they could trust were the artificial horizons. Fernández then began another descent in order to intercept the instrument landing system for runway 15, from a reported altitude of 9,700 feet — but they were actually less than half that high.</p><p>At 01:08, ATC reported that the 707 was taking off to assist them, then instructed them to fly heading 070 to intercept the ILS. By this point they were 50 nautical miles west of Lima with a ground speed of 270 knots, which was within the safe range. Still, the pilots seemed confused by the overspeed alarm as Schreiber again said, “How can it be flying at this speed if we are going down with all the power cut off?” But the airplane was under control, and as he continued their descent, Fernández commented that it was “flying well.”</p><p>Suddenly, at 01:10 and 17 seconds, the GPWS again started calling out, “TOO LOW, TERRAIN!” But at the exact same moment, the controller affirmed that their altitude was still showing 9,700 feet. “What is the indicated altitude on board? Have you any visual reference?” he asked.</p><p>“9,700 but it indicates too low terrain,” Fernández replied. “Are you sure that you have us on the radar 50 miles?”</p><p>As the GPWS continued to blare, Schreiber said, “Hey look, with 370 we have…”</p><p>“Have what? 370 of what?” Fernández asked. “Do we lower the gear?”</p><p>“But what do we do with the gear? Don’t know… that…” Schreiber started to say. Apparently he was worried about extending the landing gear while above the gear’s maximum rated speed. Their airspeed indicators showed way above the limit, so he might have been worried that the gear wouldn’t extend, or perhaps he was simply uncomfortable extending the landing gear without knowing their real speed. Regardless, the debate was purely academic, because they were still 50 miles from the airport.</p><p>At that moment, 40 seconds after the GPWS first sounded, traveling at 250 knots with a 5 degree bank to the left, the 757’s trailing left wingtip struck the surface of the Pacific Ocean, sending a massive shudder through the aircraft.</p><p>“We are impacting water!” Fernández shouted over the radio. “Pull it up!”</p><p>“Go up, go up if it indicates pull up!” the controller urged.</p><p>“I have it, I have it!” Schreiber shouted. Pulling hard on the controls, he managed to drag the wingtip out of the water, but it was too late. The impact severely damaged the left wing, leading to an imbalance of lift that was impossible to overcome. The aircraft climbed to a height of just 300 feet, then began to fall, rolling inexorably left despite the pilots’ desperate efforts to level the wings.</p><p>“We are going to invert!” Schreiber yelled.</p><p>“WHOOP WHOOP, PULL…!” blared the GPWS. But the alarm was cut off mid-annunciation by a tremendous crash as the 757, banked 70 degrees to the left, plowed headlong into the Pacific. The last sound on the cockpit voice recording was the dreadful roar of the impact. The time was 01:11 a.m. and 16 seconds.</p><p>◊◊◊</p><p>As soon as the aircraft disappeared from radar and radio contact, emergency services were notified, and vessels were dispatched to the flight’s last known location. Due to poor organization, aerial assets were not deployed until later that morning, but by then a Peruvian navy ship had already found floating wreckage and bodies on the ocean 48 miles northwest of Lima. Rescuers determined that none of the 70 passengers and crew had survived.</p><p>Later, the US Navy recovered a small amount of wreckage from the sea floor on Peru’s behalf. Among the recovered items was a mangled section of the lower forward fuselage containing the captain’s static ports. In a remarkable feat of adhesive technology, the strip of silver masking tape was still attached.</p><p>The investigation by Peru’s Accident Investigation Board (AIB) found that the accident was precipitated by maintenance missteps, as technicians covered the static ports with tape that was insufficiently conspicuous. Multiple layers of personnel, including the flight crew, subsequently failed to notice and remove the tape. In a letter written after the accident, the US NTSB noted that Airbus and McDonnell Douglas provided brightly colored static port covers for their aircraft, and at least one US airline covered their static ports using tape with brightly colored streamers attached. Neither of these products was available at Aeroperú’s maintenance facility in Lima. As a result, the NTSB and the AIB both recommended requiring the use of brightly colored flags or covers when protecting the static ports.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/960/0*vQXukzecmmKoq_6G" /><figcaption>An example of the brightly colored static port covers that were not used on flight 603. (Aviatema)</figcaption></figure><p>The loss of all static pressure data created a situation that was extremely difficult for the flight crew to understand. Broadly speaking, the airspeed data started off correct, while the altitude read too low. The airspeed then slowly started reading too low as well, until the indicated altitude nearly caught up with the actual altitude. After the plane started descending from 13,000 feet, the airspeed and altitude both started reading too high, prompting the first officer to pull back power and deploy the speed brakes. This slowed the aircraft too much, leading to a near stall. The airplane descended to less than 1,500 feet above the ground, then climbed back to 4,000 feet, during which time the altitude continued to read around 10,000 feet. After receiving valid ground speed data from ATC, the pilots more or less stabilized the flight path, then initiated a descent toward the airport. This descent continued until the aircraft struck the water.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/500/0*YGz9pabpZNJ7jVRI.jpeg" /><figcaption>The static ports from Aeroperu 603, with the tape still attached. (AIB Peru)</figcaption></figure><p>Unlike Birgenair flight 301, Aeroperú flight 603 was under control when it impacted the ocean. The aircraft collided with the sea primarily because the flight crew trusted their erroneous barometric altimeter readings, leading them to believe that they were much higher than they actually were. This misplaced trust developed because the controller kept verifying their false altitude readout using his secondary radar display. Neither the pilots nor the controller understood that ATC radar gets its altitude data from the aircraft’s own pitot-static system, which the pilots already knew was untrustworthy.</p><p>If the pilots had realized this, they could have descended until the radio altimeter came alive at 2,500 feet, then leveled off. The aircraft could then have been flown safely back to the airport at this altitude. The pilots also had ground speed indicators available in the cockpit that could have been used at an early stage to determine the reasonableness of the airspeed indications. Unfortunately, neither of these alternate systems were used.</p><p>It must be noted that it’s very easy to say, from the comfort of an armchair 30 years down the road, that they should have just used their radio altimeter and ground speed indicators. In reality, these kinds of outside-the-box ideas need to be nurtured in a stable environment. In this case the pilots never felt that the aircraft was sufficiently stabilized to engage in systematic troubleshooting, so alternative means of determining their speed and altitude were never properly considered. This is why the very first action in response to unreliable airspeed or altitude indications must be to assume a known pitch and thrust combination that will keep the aircraft in a safe, shallow climb — because there’s no time to think holistically when the airplane is threatening to stall or strike the ground.</p><p>Overall, the pilots’ actions were characterized by chaos and confusion, punctuated by moments of clarity that sadly didn’t translate into a successful outcome. Like the Birgenair flight crew, they were faced with a situation that was recoverable but ended in tragedy because of a lack of knowledge — a lack of knowledge of how the aircraft uses air data; a lack of knowledge of the symptoms of a pitot-static failure; and a lack of knowledge of strategies to ensure continued safe flight with unreliable airspeed and altitude indications. And like the Birgenair pilots, this lack of knowledge stemmed from a lack of relevant training.</p><p>While the Aeroperú and Birgenair accidents were different in some key ways, they are mentioned in the same breath not only because they involved the same type of plane and happened in the same year, but because they both could have been prevented by the implementation of unreliable airspeed training. And that brings me to the final part of this story — a survey of the extensive measures that have been implemented to prevent this sort of tragedy over the last three decades.</p><p>◊◊◊</p><h3><strong>Part 3: The Legacy Left Behind</strong></h3><p>Mere days after the crash of Birgenair flight 301, German authorities banned the airline from flying in Germany, which caused Birgenair to immediately cease operations, followed by bankruptcy later that year. Aeroperú, being a larger flag carrier, held on longer, but it too declared bankruptcy and ceased operations in 1999 following a series of costly settlements on behalf of the victims of flight 603. But the legacy of each disaster also profoundly advanced industry knowledge of the unreliable airspeed problem, ultimately kicking off a series of safety improvements that have completely transformed the way pilots handle this type of emergency.</p><p>This series of changes began within months of the two crashes, as Boeing drafted an unreliable airspeed emergency checklist for the 757 and introduced new EICAS messages that would alert the pilots if their altitude or airspeed indications disagreed. The checklist eventually spread to all Boeing models.</p><p>Soon, training scenarios based on unreliable airspeed events began to proliferate. Instead of relying solely on a checklist, manufacturers and airlines began to introduce “memory items” — actions that the pilots should take immediately from memory. On Airbus aircraft, for instance, these memory items called for the pilots to apply takeoff/go-around (TOGA) thrust and adopt a safe pitch angle, either 15 degrees below 1,500 feet; 10 degrees between 1,500 and 10,000 feet; or 5 degrees above 10,000 feet. Only then would the pilots begin troubleshooting using the checklist. All major manufacturers also introduced new quick reference handbook (QRH) pages that contain tables of thrust and pitch settings that will result in a safe flight path at a variety of aircraft weights and in different configurations, which allow pilots to quickly stabilize the situation in any phase of flight. Airlines in most countries are also now required to repeatedly expose pilots to these scenarios during recurrent training.</p><p>Later, Airbus introduced a backup speed scale (known as the BUSS). If, after following the checklist, the pilots determine that all air data units are unreliable, the checklist instructs them to turn the air data units off, which will cause the BUSS to appear. The BUSS replaces the normal airspeed scale with an angle of attack scale, depicting the boundaries of safe flight in terms of AOA instead of airspeed. In 2016, this system was further updated on some Airbus models to allow the pilots to engage the BUSS with the push of a button.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/798/1*bx_Tq6LWnywqd-nLntjsuw.png" /><figcaption>The Airbus backup speed scale, seen left of the artificial horizon. (Safety First: The Airbus Safety Magazine)</figcaption></figure><p>But even this tool is now obsolete. Some of the newest Airbuses now come with a system that automatically detects an air data unit that is providing bad data and generates a warning message indicating which unit is faulty. Additionally, this new modification includes a digital backup speed scale rendered in knots, computed algebraically by solving for airspeed in the lift equation with the angle of attack, weight, and load factor as known inputs.</p><p>If a failure results in erroneous altitude information, the newest Airbus systems can detect this, and will replace the affected altimeters with an alternate, GPS-derived altitude indication. This feature also generates a warning message prompting the crew to turn off the altitude broadcast from the transponder in order to prevent ATC from receiving erroneous altitude information.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*grC2-vgrUzq4HcM3n38nLw.png" /><figcaption>Airbus’s algebraically derived digital backup speed scale. This image comes from the A320 Mentor Channel on Youtube; watch their full video on the Airbus digital backup speed display here: <a href="https://www.youtube.com/watch?v=V4ucaXICrDY">https://www.youtube.com/watch?v=V4ucaXICrDY</a></figcaption></figure><p>On the Boeing 787, the most advanced Boeing model, bad air data can also be detected automatically by a feature that constantly compares the indicated airspeed to the algebraically derived airspeed. If a discrepancy is detected, a warning message is displayed to the crew, along with an automatic reversion to GPS altitude and/or algebraically derived airspeed if necessary.</p><p>As advanced as these systems are, not all aircraft have them, and the process of improvement continues. For instance, a 2020 study pointed out that many pilots still do not, and cannot, fully understand the air data architectures of state-of-the-art aircraft. The authors proposed to mitigate this problem with the use of newly designed synoptic pages that show how air data is flowing between different aircraft systems in real time. <em>“This technology will create procedural changes in the way pilots handle system failures, but the benefit is the significantly reduced time to complete complex checklists and a greater pilot understanding of what needs to be done and why,”</em> the study’s authors wrote.</p><p>This is far from an exhaustive list of the features incorporated into modern airliners as a result of accidents like Birgenair 301 and Aeroperú 603. It’s also far from a complete summary of the extent and nature of the training that pilots now receive. It cannot be overstated how far the industry has come since those accidents, when the pilots were given no tools whatsoever to combat one of the most insidious failures. Those men had everything stacked against them, and they lost.</p><p>Today’s pilots are drilled from an early stage to remember two items: <em>pitch and thrust.</em> Pitch and thrust are a lifeline. If you can maintain both, the airplane will stay on the great highway in the sky, even if you’re blindfolded. Only then can you have a nice conversation about the problem over a proverbial cup of tea.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/500/0*S10U1xEqch-TxpWI" /><figcaption>A monument by the sea in Puerto Plata commemorates the 121 passengers and crew from Birgenair flight 301 whose bodies were never recovered. (Wikimedia user Bellomonte)</figcaption></figure><p>Despite these measures, unreliable airspeed remains one of the trickier scenarios that a modern airline pilot might face. Very occasionally, unusual edge cases still arise that genuinely endanger the safety of flight. In those cases, good systems knowledge can easily mean the difference between life and death. In fact, the pilots in this story weren’t just flying blind because of bad data, they were flying blind because they didn’t understand their own aircraft, and because the required level of understanding wasn’t seen as important. As long as the industry doesn’t lose sight of that fact, then the 259 people who lost their lives in 1996, who were dashed against two oceans aboard two airliners that could have been saved, will not have perished in vain.</p><p>_______________________________________________________________</p><p><em>Don’t forget to listen to Controlled Pod Into Terrain, my podcast (with slides!), where I discuss aerospace disasters with my cohosts Ariadne and J! </em><a href="https://www.youtube.com/@ControlledPodIntoTerrain"><em>Check out our channel here</em></a><em>, and listen to </em><a href="https://www.youtube.com/watch?v=-i3dZNFDk84"><em>our latest episode about a titanic battle between a BAC 1–11 and some wind.</em></a><em> Alternatively, download audio-only versions via </em><a href="https://rss.com/podcasts/cpit/"><em>RSS.com</em></a><em>, or look us up on Spotify!</em></p><p>_______________________________________________________________</p><p><a href="https://www.reddit.com/r/AdmiralCloudberg/comments/1lo22kj/insidious_truths_the_crashes_of_birgenair_flight/?">Join the discussion of this article on Reddit</a></p><p><a href="https://www.patreon.com/Admiral_Cloudberg">Support me on Patreon</a> (Note: I do not earn money from views on Medium!)</p><p><a href="https://bsky.app/profile/kyracloudy.bsky.social">Follow me on Bluesky</a></p><p>Visit <a href="https://www.reddit.com/r/AdmiralCloudberg/">r/admiralcloudberg</a> to read and discuss this series</p><p><a href="https://docs.google.com/document/d/1lkYYR084z1p4uSuQb6q6LApTa0fjvBPkz-sf25cqIw8/edit?usp=sharing"><strong>Bibliography</strong></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=c7bb6228021b" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Trial by Fire: The crash of Aeroflot flight 1492]]></title>
            <link>https://admiralcloudberg.medium.com/trial-by-fire-the-crash-of-aeroflot-flight-1492-ee61cebcf6ec?source=rss-e119a26506e3------2</link>
            <guid isPermaLink="false">https://medium.com/p/ee61cebcf6ec</guid>
            <category><![CDATA[russia]]></category>
            <category><![CDATA[flying]]></category>
            <category><![CDATA[aviation]]></category>
            <category><![CDATA[technology]]></category>
            <dc:creator><![CDATA[Admiral Cloudberg]]></dc:creator>
            <pubDate>Tue, 13 May 2025 04:24:40 GMT</pubDate>
            <atom:updated>2025-08-07T06:30:53.743Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/862/0*pkKwCWi_JQkpRJCC" /><figcaption>Aeroflot flight 1492 burns to the ground after landing at Moscow’s Sheremetyevo Airport. (ABC News Australia)</figcaption></figure><p>On the 5th of May 2019, travelers at Moscow’s biggest international airport were greeted by the astonishing sight of a passenger plane skidding down the runway in flames, its tail section engulfed by a conflagration of biblical proportions. As the crippled jet slid to a stop, the doors opened, the slides deployed, and passengers ran for their lives — but for many, the evacuation was over before it even began. In the back of the plane, the fire ripped into the cabin so quickly that some passengers perished without so much as a chance to stand up from their seats, while others collapsed in the aisle, enveloped in a cloud of toxic smoke from which they would never emerge. By the time the fire was out, half the plane stood intact, while half lay in ruins; and in a chilling mirror image of the vessel that carried them, 37 people walked away, while 41 others never came home.</p><p>The crash of a Russian-built Sukhoi Superjet 100, at a Russian airport, while flying for Russia’s flag carrier, set off a circular firing squad of accusations, as observers and stakeholders alike sought to determine whether fault lay with the airline, the airplane, the flight crew, or even the passengers, some of whom stopped to retrieve their carry-on bags while their countrymen burned. But the crash of Aeroflot flight 1492 isn’t a simple story. It ended in a wall of fire, but it began with a thunderstorm, a lightning strike, and a malfunction of the fly-by-wire control system, followed by a desperate return to the airport, an unstable descent and approach, and a botched landing attempt that slammed the plane into the runway over and over until it broke. The sequence of events was so long, raising so many complex questions, that it took investigators from the independent Interstate Aviation Committee nearly six years to reach firm conclusions and publish their report, which stretches to almost 600 pages and includes two dissenting opinions. The vast quantity of primary evidence, experimental data, and expert analysis contained in this new report finally permits a reasonably objective recounting of what actually happened on that blustery day in Moscow, in the process revealing a story that is colossal in breadth, mind-bendingly technical, and yet also at times frustratingly banal.</p><p>This is that story.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/800/0*FVTbZMjLWN0hjeiq" /><figcaption>A view over Sheremetyevo Airport. (Aviation Images Ltd.)</figcaption></figure><h3><strong>Part 1: Red Alarm</strong></h3><p>To be an airport firefighter requires acceptance of the principle that anticipation is more enjoyable than gratification. Yes, once in a while a fire erupts in a trash can or a piece of luggage, or someone spills some hydraulic fluid, but a great deal of time is spent either training for or standing ready for a career-defining catastrophe that most will never see. There is a certain frustration associated with the absence of a reason to put those skills to use, albeit one that is usually dispelled as soon as such a reason actually arises.</p><p>At Sheremetyevo International Airport, the world’s gateway to Moscow, the airport firefighting service is much like any other. Although Russia has a spotty aviation safety record, Sheremetyevo had long been spared, and by May of 2019 the greatest excitement within living memory for the airport firefighting service was a 2014 blaze aboard a mothballed Il-96. In an official statement, the airport declared that the soon-to-be-scrapped airliner was destroyed as a result of “spontaneous combustion.”</p><p>The 5th of May 2019 was a turbulent spring day, with thunderstorms bubbling up across the Moscow region. At Sheremetyevo Airport, the temperature by late afternoon had reached a pleasant 15˚C, with variable winds gusting up to 54 km/h amid intermittent light rain showers. Although Russia’s meteorological service had issued SIGMET thunderstorm warnings for the area, traffic at Sheremetyevo was no less heavy than usual. Throughout the afternoon, a flight took off every two minutes, climbing into the onrushing wind before turning sharply away toward clearer skies.</p><p>Unknown to the firefighters, one of those planes was coming back.</p><p>At 18:30 local time, a tremendous bang rang out over the airport, turning heads in the terminals and on the ramp toward Sheremetyevo’s runway 24 Left. And there they saw a plane, a little silver regional jet — or rather, just half of one, because the other half was lost somewhere in a firestorm of such tremendous size that witnesses could not believe it had only just now ignited, and yet it had. Flames and smoke billowing behind its wings and tail, the aircraft rolled down the runway at low speed with its nose gear extended but its belly dragging across the ground like a wounded dog. Within seconds, it began to slew to the left, its nose pivoting to face the terminal, whereupon it briefly appeared to travel sideways before it finally ground to a halt somewhere in the vicinity of taxiway Alpha 2.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*zixrXTTdmmao4nVd.jpg" /><figcaption>A still from surveillance footage captures Aeroflot flight 1492’s fiery landing roll. (BBC News)</figcaption></figure><p>Atop a lookout tower at Sheremetyevo’s Fire Station #1, the firefighter on observation duty did not know that an aircraft had declared PAN-PAN, one step short of MAYDAY, that its crew had reported flight control problems, or that it was coming in for an emergency landing. Normally he would have this information, but today, he didn’t. He too knew only that an aircraft had burst into flames before his very eyes. Before it had even stopped moving, he pressed the alarm button and transmitted on the airport’s fire rescue channel, “Emergency! Aircraft on runway!” A brief pause followed as the burning aircraft continued down the runway in his direction, and then he repeated, “Emergency, did you copy!? Fourth runway, an aircraft is burning on the runway!”*</p><blockquote>*Although the MAK published an English translation of its report, all quotations in this article are my own translations from the Russian language report.</blockquote><p>At the terminal, cameras swiveled to focus on the burning airplane, its nose pointed right of frame, greedy tongues of fire curling around its fuselage and tail. Within seconds, the two forward exit doors opened, the slides deployed, and people began to pour down them, but behind the wings, flames were already bursting forth from the cabin windows, rippling and churning in the jet blast of the still-running engines. Burning fuel carpeted the ground in fire, silhouetting the passengers as they ran.</p><p>On the rescue frequency, the Rescue Response Supervisor announced, “Declaring alarm! To all vehicles, all firefighting vehicles are called to 24 Left immediately!” Another voice jumped in: “Attention! The alarm is declared to the emergency and rescue teams, code red! Superjet, Aeroflot airline, upon landing due to technical reasons is on taxiway Alpha, catching fire.” In response to the red alarm, the on-duty rescue teams jumped into their vehicles and peeled out of the stations with sirens blaring. But an airport is a vast place, and their arrival would not be instant.</p><p>At the aircraft, two flight attendants dressed in Aeroflot’s bright red uniform fled the cabin, one after the other. Somewhere amid the heaving smoke, the empennage burned through and collapsed to the ground.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/960/0*H6QktwDEf5pYBxBQ" /><figcaption>Passengers, ground personnel, and a flight attendant observe the burning plane. (Oleg Molchanov)</figcaption></figure><p>For a moment, no more passengers came. And then a woman threw herself down the slide and collapsed unmoving to the ground. A man followed headfirst out the door, stood up, and walked away. Behind him, another person toppled down the slide, stopped at the bottom, and rose only with difficulty. A ground handling worker, by coincidence the first airport employee to reach the scene, attempted to render assistance.</p><p>As the first fire truck approached the aircraft, it was obvious that a major disaster was unfolding. “Sirena — Strela-8, proceeding to the site,” its driver reported. “Heavy smoke in sight, black smoke, and flames. How do you copy, over? Call for additional garrison forces and an ambulance!”</p><p>The crew opened fire with the water cannon as the vehicle was still moving, throwing water onto the sizzling tail section. A dazed passenger watched, alone, from the taxiway.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Uw9dKButrGLOjxnZIJgIOA.png" /><figcaption>One of the last surviving passengers, at frame left, glances back at the plane as he walks away. (Igor Trunov)</figcaption></figure><p>Moments later, another man jumped to safety, and then a pilot appeared in the doorway, hesitating at the top of the slide, glancing back into the cabin. The other pilot opened the right-hand cockpit window and stuck his head into the fresh air as dark gray smoke poured out behind him, whipping up and over the cockpit roof. The ground handler appeared to shout at them to leave, but they did not. A second fire truck arrived and began pouring foam onto the plane, while a single firefighter tried but failed to climb up the emergency slide and enter the cabin.</p><p>Forced out by the smoke and flames, the first officer deployed the emergency escape rope and climbed down from the cockpit window. Firefighters and ramp personnel helped him to the ground, and then he ran around to the slide and stared up at the smoky darkness within the cabin, seemingly unsure what to do.</p><p>As more and more fire trucks arrived on the scene, the flames started to wither under their assault. The first officer then attempted to climb up the slide, fell, and was boosted by a ground handler. The captain appeared at the door and dragged him back aboard, no doubt to the consternation of the firefighters who were at that moment desperately attempting to save him. Seconds later, he threw his flight bag and another object down the slide, then jumped down after them, surrounded by a half a dozen white arcs of firefighting foam.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*M809uM2Trn9E7YaGT_Db8Q.png" /><figcaption>First Officer Maksim Kuznetsov exits the window of his burning airliner. (Igor Trunov)</figcaption></figure><p>For some time, firefighters and ground personnel milled about, watching the flames die down, waiting for the captain to abandon ship. After a minute, someone brought a ladder, and a man with no protective gear climbed up it, entered the cabin, reconsidered his decision, and threw himself back out the door to the ground. A better equipped firefighter followed, shouted for the captain to leave, and then backed away to give him room. Finally, the captain, too, jumped to safety. He would be the last to leave the plane alive.</p><p>◊◊◊</p><p>As medical and airport personnel gathered the passengers at the terminal, prepared the wounded for transport to hospital, and set up an information center, Aeroflot employees retrieved the manifest and conducted a headcount. A preliminary statement put out by the airline vaguely stated that “Passengers left the aircraft via the emergency exits” but did not confirm the seriousness of the accident. Russia’s Emergency Ministry even released a statement claiming that all passengers had escaped. But at that point the rescue teams already knew that a flight attendant was missing, because the captain had told them as much before he left the plane. As for the passengers, the captain had no information. And at the terminal, company personnel discovered, to their horror, that only 33 of the 73 passengers could be accounted for.</p><p>Within minutes, the fire was put out, and rescue teams entered the aircraft. There was little hope of finding anyone alive. But no one could possibly have been prepared to find so many people dead.</p><p>Initially, the regional transportation office reported one official fatality, the aft flight attendant, who was found lying on the ground outside the 2L door. But over the next few hours, the official toll rose to 10, then 13. At the airport, rumors swirled. Officials told the media that they could confirm the whereabouts of only 37 out of the 78 passengers and crew. Early the following day, Aeroflot published a list of 37 names belonging to known survivors, with an attached note. <em>“The list is incomplete,”</em> it read.<em> “As of now information regarding other passengers on the flight is being confirmed.”</em> But no more names would ever be added.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*e--Q6UUaWVCm-Hty.jpg" /><figcaption>The remains of the airplane lie next to taxiway Alpha 2 after the crash. (MAK)</figcaption></figure><p>Out on the concrete expanse of the airport, recovery crews pulled 41 bodies from the charred wreckage. They belonged to 40 passengers and one crewmember; 40 Russians and one American. As news broke of the true toll, Aeroflot put out a press release. <em>“Aeroflot extends its deepest condolences to the family and loved ones of those who lost their lives on flight SU1492 Moscow-Murmansk,”</em> the note said. “<em>The crew did everything in its power to save passenger lives and provide emergency assistance to those involved. Tragically, they were unable to save all of those aboard.”</em></p><p>Whether the crew actually did everything in their power was beside the point; it was what they were expected to say. As for the truth, reality is rarely romantic.</p><p>◊◊◊</p><h3><strong>Part 2: The First Six Minutes</strong></h3><blockquote>The following sections are based on the official report published by the Interstate Aviation Committee, or MAK (Russian: Межгосударственный авиационный комитет). The MAK is an independent, extra-governmental organization headquartered in Moscow that carries out aviation-related duties in several former USSR member states, including accident investigation. Although the MAK is not free of conflicts of interest, attempts by the Russian government to control the organization and influence its findings have historically been unsuccessful. It is one of the last remaining civil organizations in Russia that operates with a degree of intellectual freedom.</blockquote><p>Aeroflot flight SU1492 was a regularly scheduled domestic flight from Moscow to the northern city of Murmansk, located on the Kola Peninsula two degrees north of the Arctic Circle. Murmansk has many claims to fame, including the title of largest city in the Arctic, home of the world’s northernmost trolley system, and other such epithets. But the story of this flight ignores Murmansk hereinafter, because the aircraft never left the confines of Moscow Oblast.</p><p>A total of 73 passengers were booked on flight 1492, the majority of whom lived in Murmansk and were returning home from the May 1 holidays. They included doctors, civil servants, and two children aged 11 and 12. Only one was a foreigner, 22-year-old recent college graduate Jeremy Brooks, an accomplished fly fisher from the US state of New Mexico, who had landed a coveted job as a tour guide in Russia’s northwestern Arctic.</p><p>The aircraft rostered for the flight was a Sukhoi Superjet 100 that rolled off the assembly line in August 2017 at the assembly plant of Russia’s United Aircraft Company, located in the far eastern city of Komsomolsk-on-Amur. The small jet could carry up to 87 passengers and was designed for short to medium haul regional flights with a crew complement of either four or five.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1000/0*Saxt1KKJL0OiU2GA.jpg" /><figcaption>RA-89098, the aircraft involved in the accident. (Miklos Szabo)</figcaption></figure><p>The three-member cabin crew consisted of 27-year-old Senior Flight Attendant Kseniya Fogel’, who was seated in the front alongside 34-year-old flight attendant Tatyana Kasatkina; and alone in the back sat the most junior crewmember, 21-year-old flight attendant Maksim Moiseev. Up in the cockpit, the second in command was 36-year-old First Officer Maksim Kuznetsov, a relatively new pilot who had joined Aeroflot with no previous experience and had since accumulated 765 hours, almost all on the SSJ-100, over 11 months with the airline. And in command was 42-year-old Captain Denis Yevdokimov, a moderately experienced pilot with about 6,800 flying hours, including more than 1,500 on the SSJ-100, which he had flown for Aeroflot since 2016. Before that, he had flown the Let L-410, Yakovlev Yak-52, and Ilyushin Il-76 for the Russian Federal Security Service, followed by a stint in the Boeing 737 at independent airline Transaero, until he was dismissed following that airline’s bankruptcy. Aeroflot picked him up a month later.</p><p>Well prior to the flight’s scheduled departure at 17:50, the flight crew went to the dispatch office at Sheremetyevo to receive their pre-flight briefing and accept the paperwork. This included discussion of the latest weather reports.</p><p>At that time, the weather in the Moscow area was unsettled, with thunderstorms beginning to move through the region from southwest to northeast. As mentioned earlier, a SIGMET, short for significant meteorological information, was in effect for the Moscow Flight Information Region due to thunderstorm activity, and a separate bulletin warned that rapid changes in wind speed and direction, known as windshear, would be present at Sheremetyevo between 16:00 and 20:00. The terminal aerodrome forecast for that same period called for winds out of the south at 15 knots, gusting to 29 knots, with 10 kilometers visibility and sporadic thunderstorms. The latest actual weather observation was in line with the forecast, with winds out of the southwest at 15–29 knots, visibility 7 km, light rain showers, broken cumulonimbus clouds with a base at 1,590 meters, temperature +15˚C, and a wet runway.</p><p>After the accident, Captain Yevdokimov stated that during the briefing, he identified no significant weather requiring special discussion, despite the fact that all of the above information was included in the paperwork. Given the existence of an active SIGMET, his assertion seems far-fetched. If there was no discussion of the SIGMET, then the briefing certainly fell far short of what was expected and required. However, the official opinion of the Interstate Aviation Committee is that Yevdokimov most likely knew about the thunderstorms all along.</p><p>At 17:16, the crew boarded the aircraft at the gate to begin preparing it for flight. They reviewed the technical log and found that no outstanding defects had been reported. Later analysis showed that the fuel tank inerting system,* which is designed to prevent the formation of an explosive fuel-air mixture in partially full or empty fuel tanks, was not working. The system had been repeatedly found inoperative on this aircraft throughout 2018 and 2019, and it was legal to fly without it for up to 7 days. That being said, this flaw turned out to have nothing to do with the fate of flight 1492.</p><p>*<em>See </em><a href="https://admiralcloudberg.medium.com/memories-of-flame-the-crash-of-twa-flight-800-fecfd651a157"><em>my article on TWA flight 800.</em></a></p><p>At 17:25, the pilots tuned in to the Automated Terminal Information System, or ATIS, to hear the latest weather observations. The ATIS showed there had been an improvement since the weather briefing. However, at that very moment, the Terminal Doppler Weather Radar (TDWR) at Moscow’s Vnukovo Airport was picking up a band of thunderstorms about 40 km southwest of Sheremetyevo, moving northeast at 30 knots, with multiple red-colored cells indicating intense precipitation. Color images from the Vnukovo TDWR were available at the Sheremetyevo meteorological office, but they weren’t provided to the crew. Nevertheless, they had plenty of textual information suggesting that a thunderstorm encounter was possible during departure.</p><p>As the crew set up the aircraft, the Sheremetyevo clearance delivery controller relayed the route they could expect to take after takeoff, which in this case was the KN 24E Standard Instrument Departure, or SID. This SID featured a westbound heading after takeoff from runway 24 Center to a point 15 km west of the airport, followed by a sweeping right turn onto a northeasterly heading to the KN radio beacon. From there, they could proceed in the direction of Murmansk.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*p5kiPZvQGf3XARdPzhIinQ.png" /><figcaption>Map of the KN 24E Standard Instrument Departure. (MAK)</figcaption></figure><p>Evaluating the assigned SID, Captain Yevdokimov said, “It’s all the same, to the right, it’s just that some kind of buildup is back there. So it will be even faster for us.” Most likely he was observing that the SID would take them close to the thunderstorms southwest of the airport, and that a quick right turn might help avoid them. In his interview, Yevdokimov explained that he made these comments after visually noticing clouds in the takeoff direction, because he hadn’t turned on the weather radar yet. However, the flight data recorder captured him adjusting the range setting on the weather radar between 5 and 40 nautical miles at this time, suggesting that the radar was in fact turned on, and that he probably saw the thunderstorm buildups on it.</p><p>As the pilots finished up their pre-flight checks and the passengers boarded, they briefly discussed their clearances, and then Captain Yevdokimov gave a passenger announcement. <em>“Good day ladies and gentlemen, this is the aircraft commander speaking, my name is Denis, I welcome you aboard this aircraft belonging to Aeroflot, one of the oldest and most famous airlines in the world. In March of 2019 Aeroflot turned 96 years old. Our fleet is one of the newest in the world. Today we’re flying the route Moscow Sheremetyevo to Murmansk. Get ready for a pleasant journey, the en route time will be 2 hours exactly. I’m sure you will enjoy your journey with Aeroflot, thank you for choosing us. I wish you a pleasant flight.”</em></p><p>Up in the cockpit, Captain Yevdokimov’s actual mood wasn’t quite so cheery, as he expressed frustration with delays at the airport. The flight finally received clearance to taxi at 17:50, its original departure time, and they taxied to the back of the line of aircraft waiting for takeoff. While waiting, Yevdokimov flicked his weather radar’s range setting back and forth between 5 and 20 nautical miles, prompting him to ask, “The buildup, can you see it en route?” But the report does not mention any response from the first officer.</p><p>Moments later, at 18:02, flight 1492 was cleared to take off, 12 minutes behind schedule. As they sped down the runway, Yevdokimov’s weather radar was set to 5 NM, while First Officer Kuznetsov had his set to 10 NM, neither of which was far enough to see the thunderstorms in their path. In fact, the flight crew training manual urges pilots to avoid red precipitation cells by at least 20 NM due to the possible presence within such cells of severe turbulence, lightning, hail, and other hazardous phenomena. Avoiding a cell by more than 20 NM self-evidently requires a range setting above 20 NM, and it was unclear why the pilots would use a range setting too short to effectively support thunderstorm avoidance. Furthermore, despite twice commenting on the buildups, neither crewmember articulated a plan to avoid them.</p><p>Flight 1492 lifted off normally and began climbing toward their initial cleared altitude of 1,200 meters above airport level, following the SID to the letter.* But both ahead and behind them, other flights were not doing the same. Between 17:57 and 18:08, three Aeroflot flights and one Czech Airlines flight departing in the same direction as flight 1492 all requested hard right turns off of the SID to avoid the approaching thunderstorms, although the crew of flight 1492 were unaware of this. Strictly speaking, it would have been proper for the controllers to ask whether flight 1492 intended to deviate too, but they did not. Even so, the crew should have independently asked to initiate the right turn to the KN beacon early, instead of flying so far outbound in the direction of the storm cells. But in the cockpit, there was no discussion of this matter at all.</p><blockquote>*Unlike most of the world, Russian aviation uses meters for altitude, and height above airport level instead of height above sea level, during low-altitude flight.</blockquote><p>After initially leveling off at 4,600 feet, the airport radar controller cleared flight 1492 onward to 7,000 feet and handed them over to Moscow Approach. While climbing to this new altitude, Captain Yevdokimov used the autopilot heading select knob to initiate the right turn, only about 1.5 kilometers earlier than called for the in the SID, without requesting a deviation. By now it was already too late to avoid cutting through the advancing northeastern edge of an intense thunderstorm cell.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qvYx9S2x2yH_DfKG0XYpxQ.png" /><figcaption>The TDWR only updated every 5 minutes, so this is where the clouds were at 18:05 (15:05 UTC). Keep in mind that the group of cells was moving northeast at 30 knots. (MAK)</figcaption></figure><p>After the accident, Captain Yevdokimov insisted that at no point before or after departure was he aware of any red-colored, high-intensity cells on his weather radar. In fact, he asserted that the radar showed only green-colored, low-intensity returns in the vicinity of the SID. Further, he explained that his slightly early right turn was intended to stay away from a green-colored cell in order to spare the passengers some light turbulence, with no need to request a full deviation from air traffic control. However, the Interstate Aviation Committee believes that these statements were false, as the weather radar was found to be functioning normally and would have displayed the red cells also seen by the Vnukovo TDWR. Additionally, the range setting at several points was long enough for the cells to show up, and the flight crew’s discussion of “buildups” suggests that they did observe these cells.</p><p>The time at which flight 1492 began to turn right corresponded quite closely to the moment at which the red cells would have become visible on the captain’s weather radar display with the 5 NM range setting. But by the time he started the turn, it would have been evident that an encounter with the severe weather was unavoidable. In fact, at 18:07, Yevdokimov said, “It’s going to get bumpy now,” to which First Officer Kuznetsov exclaimed, “Crap.”</p><p>“It will be fine,” Yevdokimov assured him. But a few seconds later, at 18:08, one of the pilots activated continuous ignition for both engines, consistent with the procedure for flying in heavy precipitation. Using continuous ignition makes the engines more resilient against flameouts caused by heavy rain or hail. This decision confirms that the crew knew they had flown into an intense thunderstorm cell.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*RhzBoJYWXxXrKPud_TurCQ.png" /><figcaption>The actual path of flight 1492 relative to the SID. Add three hours for local time, used in this article. (MAK)</figcaption></figure><p>The question of why they failed to take evasive action before reaching the storm is one that no doubt haunted the MAK throughout its investigation; and with the pilots refusing to cough up the truth, there isn’t an easy answer. My suspicion is that the driving factor was complacency, that quirk of human cognition that makes us think, “Those buildups are far away, we can complete the SID before they get here, asking for a deviation is annoying, everything will turn out fine.” But that’s the kind of thinking that airmanship is supposed to overcome. Tragically, in this case it did not.</p><p>Of course, pilots are trained to avoid thunderstorms for a reason. The hazards lurking within them are multifarious and unpredictable. Captain Yevdokimov and First Officer Kuznetsov knew that, as all pilots do, but apparently they needed a reminder. And at time 18:08 and 9.7 seconds, they got one.</p><p>At that precise instant, passengers and crew heard a sharp bang and perceived a blinding flash of light as a bolt of lightning surged through the aircraft, for a split second uniting the Superjet, the cloud, and the ground along a white-hot river of electrons. And then, all hell broke loose.</p><p>◊◊◊</p><h3><strong>Part 3: The Post-Industrial Plane</strong></h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*qvs0rS9i1b8ckn-K.jpg" /><figcaption>Sukhoi Superjet 100s on the assembly line in Komsomolsk-on-Amur in 2015. (TASS)</figcaption></figure><p>In the 1990s, the collapse of the Soviet Union and the privatization of air travel decimated Russia’s aviation industry, as demand for air travel dropped by nearly 80% and state spending on research and development essentially disappeared. By the time Russia’s economic ship started to right itself, almost no progress had been made on the next generation of Russian airliners. To make matters worse, the capabilities of Russia’s high-tech manufacturing sector were at least 20 years behind the United States and Europe, and were falling further behind with each passing year. Previously, Russian aircraft manufacturers didn’t have to worry about competing with their Western counterparts, and now that they did, they found that no Russian suppliers were capable of producing the advanced equipment needed to match their rivals’ performance, particularly in the realm of engines and avionics. Russian airlines flocked to the sales desks of Airbus and Boeing and mothballed their Tupolevs and Ilyushins. Sales of existing Russian-built aircraft fell to dire levels. In 2000, Russian companies managed to build just four commercial airplanes.</p><p>During the early 2000s, the Russian government sought to reverse the fortunes of its moribund aircraft manufacturing industry by uniting all of Russia’s major aircraft manufacturers, including Ilyushin, Tupolev, Yakovlev, and Sukhoi, into the United Aircraft Corporation. UAC mostly produced, and still primarily produces, military aircraft. But the long-term goal was always to revive the design and manufacture of civilian airliners. The first of those models, and to date the only one that has actually entered service, was the Sukhoi Superjet 100.</p><p>The Superjet, or SSJ for short, was envisioned as a medium-range regional jet with five abreast seating and a passenger capacity similar to Brazil’s Embraer ERJ series, without competing directly against the larger Airbus and Boeing models that dominated Russia’s airlines. The SSJ was designed with a sidestick-operated fly-by-wire control system, similar to Airbus, although contrary to popular belief it was not the first fly-by-wire Russian airliner; that title belongs to the commercially unsuccessful Tupolev Tu-204, which entered production in 1990, shortly before the collapse of the Soviet Union.</p><p>UAC hoped to gain enough of the regional jet market to produce several hundred aircraft, and in order to have any hope of competing, it would have to seek help from the West. In the 2000s and early 2010s, relations between Russia and the West were cordial enough; the former Cold War rivals certainly were not friends, but the political landscape was much friendlier than it is today. As a result, UAC was able to contract extensive advisory services from Boeing, while the engines were designed and produced by a partnership between French manufacturer Safran and the Russian firm NPO Saturn. The avionics were largely designed and built by aerospace companies Thales (of France) and Honeywell (of the United States), while Safran constructed the landing gear, Liebherr (of Germany) built the flight controls, and B/E Aerospace (of the United States) provided the cabin furnishings and doors. Russian suppliers built the fuselage and wings. Foreign parts were imported to Russia and final assembly took place at UAC’s assembly plant in Komsomolsk-on-Amur.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/960/0*S0nTZZUrAhr12A-T" /><figcaption>All the SSJ-100’s foreign suppliers. These were once considered a selling point, but due to sanctions on Russia they are now a liability. (Sukhoi Aircraft Company)</figcaption></figure><p>The final design of the SSJ bears some resemblance to an Airbus aircraft, but perhaps not quite as much as is sometimes suggested. Although the individual suppliers were also major suppliers of Airbus and Boeing, the design specifications for the SSJ were drafted primarily by UAC, with only advice from foreign manufacturers, and as a result the designs of its key systems differ from their Airbus counterparts in some ways that are of significance to this story. The details of those systems will be discussed later in this Part.</p><p>The SSJ-100 first flew in 2008, and after passing certification by the Russian Federal Air Transport Agency (FATA, popularly known as Rosaviatsiya), the European Aviation Safety Agency (EASA), and the Interstate Aviation Committee’s aircraft certification division,* the type entered service with Armenian flag carrier Armavia in 2011. The celebration was short-lived, however, as Armavia cancelled its remaining orders and sent its two SSJs back to the manufacturer in 2012, citing a high rate of technical failures and the high cost of spare parts. Also in 2012, an SSJ carrying airline executives on a demonstration flight in Indonesia crashed into a mountain, killing all 45 people on board. No Indonesian airlines ordered the SSJ, even though the crash was found to have been caused by a series of errors by the Sukhoi test pilots.</p><blockquote>*One of the MAK’s inherent conflicts of interest as an investigating body is its secondary role as the guarantor of aircraft type certificates in its member states. The MAK has not held this responsibility in Russia since 2016 and was not responsible for the SSJ-100 type certificate during the investigation into flight 1492, but it was responsible at the time the SSJ-100 was originally certificated. The validity of the MAK’s conclusions regarding certification issues during the Aeroflot 1492 investigation is discussed in Parts 6 and 8 of this article. For more information on the history of the MAK, its potential conflicts of interest, and why its certification roles were taken away, see <a href="https://docs.google.com/document/d/1hVnzJ6HqgOxKUYZX2m5fUXPHipSf_j4U/edit?usp=sharing&amp;ouid=100007588750159924865&amp;rtpof=true&amp;sd=true">this paper </a>I wrote in 2021 on the demise of Transaero.</blockquote><p>The aircraft’s unreliability seriously harmed sales, and the second customer, Russian flag carrier Aeroflot, had to be plied with steep discounts and free support packages before agreeing to order a final total of 50 SSJ-100s. Aeroflot executives reported in 2012 that the planes were achieving less than half their expected utilization, measured in terms of flight hours per day, due to a combination of frequent mechanical failures and slow delivery of spare parts. The exact reasons for these issues are subject to debate among the parties involved, but importing spare parts to Russia has always been difficult due to extensive red tape, which at the very least exacerbated the issue, given that so many aircraft systems were manufactured abroad. But red tape couldn’t have been the only reason, because some of the few foreign airlines who gave the SSJ a try, including Ireland’s CityJet and Mexico’s Interjet, encountered the same problems. In fact, the serviceability rate of the SSJ-100 still has not caught up with newly released Airbus aircraft even after 14 years in service.</p><p>I’m planning to take a closer look at the SSJ’s design, development, and service history in an eventual episode of my podcast, Controlled Pod Into Terrain. But for the purposes of this article, I want to focus on one particular manifestation of the type’s unreliability, and for that we need to take a look at its fly-by-wire system.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/960/0*5DDY1f9LOfjKKJ1Y" /><figcaption>A CityJet SSJ-100 in Dublin, Ireland in 2016. CityJet replaced its SSJ-100s with CRJ-900s in 2019 due to insufficient reliability. (Alessandro Ambrosetti)</figcaption></figure><p>◊◊◊</p><p>The term “fly-by-wire” refers to a control system that transmits pilot inputs to the control surfaces by electronic means. Fly-by-wire systems have a number of advantages over conventional control systems that utilize physical cables, including reduced pilot workload, decreased weight and complexity, high capacity to tune out undesirable control characteristics, and the ability to impose limitations on the flight envelope. The design philosophy was pioneered by various military aircraft, as well as Concorde, and was first used in a mass-produced airliner when Airbus introduced the A320 in 1988. Since then, the concept has spread throughout the industry, and most newly designed passenger jets today incorporate at least some fly-by-wire elements.</p><p>In basic terms, a fly-by-wire control system relies on a network of sensors that measure speed, pressure, temperature, attitude, angle of attack, and a host of other parameters. These raw data are fed to several sets of double- and triple-redundant computers that check it for validity, calculate secondary parameters, and distribute them to the computers that interpret pilot control inputs and translate them into actual control surface movement.</p><p>An important issue that differs between conventional and fly-by-wire aircraft is the variation in control surface response at different airspeeds. Due to faster airflow over the control surface, the same control deflection will result in a larger aircraft response at high airspeed, and a smaller response at low airspeed. Without feedback, this would cause the pilot to overcontrol the aircraft at high speeds. In a purely cable-operated aircraft, this problem solves itself because the increased aerodynamic load at high speeds makes it harder to deflect the controls. In a conventional aircraft with hydraulically boosted controls, an artificial feedback device mimics that extra load. But on the fly-by-wire Airbus and SSJ-100, there’s no force feedback at all — instead, computers adjust the ratio of sidestick travel to control surface deflection in real time with respect to airspeed so that the aircraft response is always the same for a given sidestick input, no matter how fast the airplane is traveling.</p><p>On a conventional aircraft, the parameter directly controlled by the pilot’s yoke is control surface deflection. But on the Airbus and the SSJ, the answer varies depending on the control axis. In the roll axis, the sidestick commands a roll <em>rate</em>, and the ailerons deflect in the manner required to achieve that roll rate. The maximum roll rate is limited by the computers to a safe value, as is the maximum allowable bank angle.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/675/0*rWSkGmT97Rh8cz2M.jpg" /><figcaption>The cockpit of an SSJ-100. Note the sidesticks on the far left and right sides. (Jordan Tan)</figcaption></figure><p>Meanwhile in the pitch axis, sidestick movement commands a particular load factor, expressed in terms of G force. At rest, the load factor is 1; that is to say, 1G, normal gravity. Pulling the sidestick back causes the load factor to increase, while pushing it forward causes the load factor to decrease. Let’s say you pull the sidestick back far enough to command a load factor of 1.2 — in that case, the airplane will pitch up at a rate that the occupants experience as a G-force 20% above normal gravity. The longer you hold the stick in that position, the more the plane will pitch up, because the pitch has to be actively increasing in order to induce a load factor above 1. When you release the sidestick back to neutral, the pitch will stop changing and will remain at its current value, causing the load factor to return to 1.0. The computers also impose a maximum and minimum pitch angle, a maximum angle of attack, and a maximum and minimum load factor, all of which will limit how much and how quickly the pilot can change the airplane’s pitch.</p><p>Some people who know very little about airplanes assume that to make the airplane climb or descend, one simply points the airplane up or down and then releases the controls. That’s how it works in some video games, like Grand Theft Auto. Those who know a little bit more about airplanes understand that that isn’t the case — if you push forward on the controls, the plane will start descending, yes, but when you let go, it will actually level off again by itself due to its inherent pitch stability. But if you study even further, you’ll learn that for many fly-by-wire aircraft, including the Airbus and SSJ-100, the Grand Theft Auto players are actually right. If you pull back on the stick in an A320 or SSJ until the plane is climbing with a 5-degree nose up attitude, then let go of the controls, the plane will keep climbing in a 5-degree nose up attitude until you tell it to do something else. After all, changing the pitch changes the load factor — but when the sidestick is at neutral, the load factor is always precisely 1, so the pitch can’t change if you’re not moving the sidestick. But how is that accomplished exactly?</p><p>A conventional aircraft returns to level flight when you let go of the controls because of the influence of the trimmable horizontal stabilizer. The position of the horizontal stabilizer determines the pitch angle at which the plane is stable — the angle it will naturally return to when you’re not making control inputs, the angle where all the forces acting on the aircraft are perfectly balanced, as all things should be. Move the stabilizer down, and the plane will be happiest at a higher pitch. Move it up, and the plane will prefer lower. On a conventional airplane, the pilot or autopilot adjusts, or trims, the stabilizer whenever the aerodynamic forces are no longer balanced. If you want to hold a pitch of 5 degrees up but the plane wants to rest at only 2 degrees up, then you trim the stabilizer nose up until the plane sits most happily at 5 degrees.* Pilots of these aircraft types are taught that if they have to apply force to achieve the desired flight path, then they should re-trim the stabilizer until they no longer have to.</p><blockquote>*Actually when you get down to it on a conventional aircraft the stabilizer determines what SPEED the aircraft is at rest, but for the purposes of this explanation, bear with me.</blockquote><p>Fly-by-wire aircraft aren’t magic, so they also have a trimmable horizontal stabilizer. The difference is that on most Airbuses and the SSJ, the pilot never has to touch it. Instead, on these aircraft a system called autotrim constantly adjusts the stabilizer in the background in order to ensure that the aircraft’s stable pitch angle is always equal to whatever pitch angle the pilot last commanded using the sidestick. So if you pull back on the sidestick, wait for the pitch to reach 5 degrees nose up, and then let go, the plane will stay at 5 degrees nose up because the autotrim has helpfully re-trimmed the stabilizer to maintain a +5˚ pitch. If you want to return to nose level, you just push forward until the nose is level, then let go, and voila.</p><p>While all of these features make fly-by-wire aircraft easier to fly and potentially safer, these systems also rely on a constant flow of accurate sensor data. If sensors become blocked, malfunction, or lose connection, then it may not be possible for the fly-by-wire computers to support their normal functions. Similarly, if the computers that process and distribute that sensor data malfunction or lose power, then these functions also won’t work. And this issue brings us to the topic of control laws.</p><p>Readers who are familiar with certain infamous Airbus accidents like <a href="https://admiralcloudberg.medium.com/the-long-way-down-the-crash-of-air-france-flight-447-8a7678c37982">Air France flight 447</a> should be familiar with the concept of control laws. Up until this point, everything I’ve said about the Airbus and SSJ fly-by-wire systems applies to the control system in “normal law,” which is the default configuration when everything is working properly. But the way the control laws change under certain failure conditions is one of the major differences between the Airbus and SSJ fly-by-wire systems.</p><p>On the Airbus, certain combinations of sensor, computer and system failures can cause the control system to revert to Alternate Law. This control law has a couple of different sub-laws with different characteristics, but broadly speaking, Alternate Law removes support for most flight envelope protections (such as high speed protection, high angle of attack protection, and so on). Sidestick movement on the pitch axis still commands a load factor, and load factor protection remains, but depending on the applicable sub-law, control surface deflection may not be adjusted for airspeed (which is what occurred on Air France flight 447 when all three sources of airspeed data were lost; see my previous article on that accident, linked above). In the roll axis, the sidestick ceases to command a roll rate and a direct relationship between sidestick deflection and aileron deflection is established instead. Autotrim continues to function normally.</p><p>If certain very serious combinations of failures occur, the control system may revert to Direct Law instead of Alternate Law. According to SkyBrary, an Airbus will enter direct law “<em>if there is failure of all three inertial reference units or all three primary flight computers, faults in both elevators, or flame out of both engines concurrent with loss of [primary flight computer] 1.”</em> Additionally, Direct Law will also engage on some Airbuses if the aircraft is already in Alternate Law and the pilot extends the landing gear.</p><p>In Direct Law, sidestick deflection is directly related to control surface deflection in all control axes. Autotrim is lost and all flight envelope protections are removed. In the yaw axis, automatic turn coordination (deflection of the rudder during a turn to prevent development of a sideslip) will also be lost, as will the yaw damper (which suppresses the airplane’s natural tendency to gently weave from side to side).</p><p>There is one last level below this, called Mechanical Backup, which relies entirely on backup cables connecting the pilot’s controls to the horizontal stabilizer and rudder, without the use of the elevators or ailerons. This law comes into play only in the event of a complete loss of electrical power, mostly to cover the few seconds in between a total power loss and the automatic deployment of the ram air turbine, which provides emergency electrical power. As far as I know, there has only been one noteworthy case of an Airbus entering Mechanical Backup, which you can read about <a href="https://admiralcloudberg.medium.com/the-dark-side-of-logic-the-near-crash-of-smartlynx-estonia-flight-9001-68b9f42b1fb2">here.</a></p><p>All of that may be familiar to frequent readers of my work, but the SSJ works a little bit differently. The Superjet doesn’t have an equivalent of Airbus’s Alternate Law; instead, most failures that would cause an Alternate Law reversion on the Airbus cause the SSJ to enter Direct Mode* instead. The SSJ does have an in-between category called the “simplified regime” (Ru: упрощенный режим), but it should not be mistaken for Alternate Law. There is no unified logic underpinning the simplified regime; rather, it’s a collection of minor defects that affect the fly-by-wire logic in some way, with the exact consequences dependent on the individual failures. For example, the loss of the stabilizer position signal will result in the loss of autotrim functions, while the rest of the system continues to operate as normal. The effects of each failure and the required crew actions are displayed to the pilots on the Crew Alerting System, an electronic warning display almost identical to Airbus’s ECAM (“electronic centralized aircraft monitor”).</p><blockquote>*In SSJ documentation, the control regimes are referred to as “modes” rather than “laws.”</blockquote><p>According to the SSJ-100 flight crew operations manual (FCOM), the control system will enter Direct Mode in the event of a loss of signal from all three air data computers (ADCs), all three inertial reference systems (IRSes), or all three primary flight control units (PFCUs). Much like on the Airbus, the system will reject the data from one or more ADCs or IRSes if the data does not pass certain validity and sanity checks. Practically speaking, this means that if all sources of a particular crucial parameter are lost, let’s say airspeed, then all three ADCs will flag this data as invalid and stop providing it to other systems. This is considered a loss of signal from all three ADCs, and a reversion to Direct Mode occurs. That’s because many fly-by-wire functions require valid airspeed data, and the SSJ has no Alternate Law that nixes those functions while preserving the rest. In fact, if Air France flight 447 was an SSJ, it would have reverted to Direct Mode.</p><p>Direct Mode on the SSJ is basically the same as Direct Law on the Airbus. Sidestick deflection has a direct relationship with control surface deflection, there’s no autotrim, no turn coordination, no automatic deployment of the ground spoilers on touchdown, no yaw damping, and so on. And because many conditions that would send an Airbus into Alternate Law will send an SSJ into Direct Mode, this control law is much more likely to activate on an SSJ than it is on an Airbus. I don’t claim to know why Sukhoi’s engineers decided to design it this way, but if I had to guess, it was probably just because it was simpler — less code to write, fewer sub-states to learn. However, it also comes with some drawbacks, because flying the aircraft is harder in Direct Mode than it is in Airbus’s Alternate Law, and consequently demands more skillful piloting. It’s also unclear how well Sukhoi understood its own control system laws, because according to a footnote in the MAK report, at the time of the accident the flight crew operations manual (FCOM, a Sukhoi product) contained descriptions of Airbus controls laws instead of SSJ control laws. The reasons for this darkly hilarious mix-up are not elucidated in the report.</p><p>◊◊◊</p><p>The probability of certain failures and their effects on crew workload and aircraft controllability are assessed in detail during the design and certification process. Potential failure scenarios are classified according to four main categories, called “minor,” “major,” “hazardous,” and “catastrophic.” A “catastrophic” failure means that preventing fatalities is “practically impossible,” while a hazardous failure is a “significant” degradation that requires the pilot to exercise a high level of skill and judgment. A “major” failure is a “noticeable” degradation that causes difficulty, while a “minor” failure is a “slight” degradation that only marginally affects the pilot’s workload. The category of a failure influences how many redundant systems must be in place to prevent it, as well as the maximum failure rate that is considered acceptable.</p><p>During certification of the SSJ, a reversion to Direct Mode was classified as a “major” failure during a non-precision approach or go-around, and a “minor” failure during other phases of flight. Because all pilots learn to fly a conventional aircraft before flying the SSJ, it was believed that pilots would already possess most of the basic skills required to fly in Direct Mode, such as manual trim, manual turn coordination, and use of direct linked controls. The lack of force feedback would present some difficulty, especially during complex maneuvers like a go-around, although the emergency procedure for a Direct Mode reversion imposed a low maximum permissible speed in order to reduce the risk of pilots overcontrolling the airplane at high speeds. It was also possible that pilots could become too accustomed to the fly-by-wire system and “unlearn” some of those basic airmanship skills, but this was not enough for the Direct Mode reversion to be classified as “hazardous.”</p><p>Before the SSJ entered service, UAC calculated that the probability of a Direct Mode reversion should be approximately 1 per 1.64 million flight hours. However, when SSJ deliveries started ramping up in 2014 and 2015, cases of Direct Mode reversions quickly began to occur. In 2015 alone, there were three such events, even though the entire SSJ fleet had accumulated just 81,000 flying hours. By 2022, the number of known Direct Mode reversions had risen to 21, for a rate of 1 per 63,000 flight hours — almost 26 times higher than the rate calculated by the manufacturer. Even worse, there wasn’t one single reason behind the massively elevated failure rate. A pair of software updates in 2017 and 2022 addressed the causes of 11 of these incidents, but no common cause for the remaining 10 has been identified to my knowledge. The MAK report states that by 2022, the SSJ-100 fleet had collectively flown 1.32 million flight hours, meaning that the expected number of Direct Mode reversions as of that date should have been about one, two if we’re being generous. Clearly this is a problem that as of 2022 had still not been resolved.</p><p>UAC did not call on airlines to provide more training on Direct Mode even in light of these events. But in 2015, after the first few incidents proved that Direct Mode reversions were more common than previously thought, a meeting was held at a high level within Aeroflot, during which it was determined that the amount of training on flight in Direct Mode should be increased. It is unclear exactly what changes were made.</p><p>According to the training program envisioned by UAC and implemented by Aeroflot at the time of the accident, a pilot undergoing initial training on the SSJ would complete a single simulator exercise involving flight in Direct Mode during descent, instrument landing system approaches, go-arounds, circle-to-land maneuvers, crosswind landings, and stalls.</p><p>After completing their type rating and joining the line, pilots continue to undergo extensive emergency drills simulating a wide variety of failures, repeated every 6 months to 3 years at recurrent training. The Sukhoi Superjet 100 training program specifies no less than 450 failures to be practiced at recurrent training on either 7 month or 3 year intervals — about the same number as the A320, for the record. However, because it’s not practical to review so many different failures individually during each pilot’s limited available simulator time, it’s common practice to combine several related failures into a single scenario exercise instead. In the case of Aeroflot’s SSJ-100 training program, flight in Direct Mode was not considered a hazardous failure requiring its own scenario, so the requirement to practice Direct Mode flight was incorporated into the simulator scenario for unreliable airspeed, because a loss of valid airspeed data will cause a reversion to Direct Mode. However, this approach can be risky because the focus is on the trainee’s handling of the primary failure, and the need for more training on secondary issues like flight in Direct Mode might be overlooked.</p><p>After the accident, the MAK sought to verify how much time was actually spent flying in Direct Mode during initial and recurrent training at Aeroflot, but they ran up against a brick wall of silence. Aeroflot didn’t keep detailed records of what exercises were practiced at each simulator session or how much time was spent on each one. In some cases, the training form had not even been filled out and the checkbox indicating completion of the Direct Mode module was empty. And when the MAK tried reaching out to the instructors who supervised Captain Yevdokimov and First Officer Kuznetsov during their initial and recurrent Direct Mode exercises, the instructors either didn’t answer or submitted pro-forma responses containing no useful information.</p><p>The MAK found numerous other discrepancies in both pilots’ training histories. During the captain’s initial training on the SSJ, 30 hours of briefings and debriefings had been improperly logged as simulator time, as a result of which he only spent 58 hours in the simulator out of a required 88. The type rating course required what Aeroflot called an “Aerodrome drill,” which was a check of piloting skill during several approaches in the real aircraft; Yevdokimov received his type rating endorsement without completing the drill or receiving the required instructor’s mark. Meanwhile, First Officer Kuznetsov was supposed to have undergone a psychological evaluation before beginning his type rating course, but this was not done until after the course had been completed. In several cases, both pilots were advanced to the next stage of training before completion of the paperwork certifying that they had passed the previous stage.</p><p>One of the more significant issues in the eyes of the investigation was a lack of consistent instructor assignments during both pilots’ initial training, and especially First Officer Kuznetsov’s. In Russia, it has traditionally been understood that the best training outcomes are achieved by assigning a trainee to a single instructor throughout the entire training period so that the instructor can gain an intimate knowledge of the trainee’s strengths and weaknesses. A consistent instructor will deliver a consistent training style and will more effectively identify and correct the areas where a trainee might struggle. But records showed that Kuznetsov was shuttled back and forth between numerous instructors throughout his initial training; for instance, just during the period from 8 August to 1 October 2018, he was assigned to no less than nine different instructors. And after he graduated to the rank of probationary first officer, the normal practice would have been to assign him to a regular captain until he had accumulated a certain number of hours, but Kuznetsov’s assigned captain was changed no less than four times.</p><p>It must be noted that changing instructors is not always a problem, and can even be beneficial because different instructors may identify deficiencies that others missed or provide useful alternate perspectives. This holds true as long as there is a consistent standard for assessing a trainee’s progress that can be passed from one instructor to the next. Most likely, the MAK did not believe such a standard existed, considering the generally poor record-keeping at Aeroflot’s training department, which explains why the investigators pointed to the constant instructor changes as a possible contributor to the pilots’ failure to fully develop their piloting skills.</p><p>Data from previous incidents showed that the crew of flight 1492 were not the only pilots who had been failed by both Aeroflot’s Direct Mode training and the airline’s training program as a whole. The MAK acquired data from seven Direct Mode reversion events between 2015 and 2018, including six from Aeroflot and one from another Russian airline, and the results painted a dismal picture of Russian pilots’ ability to handle this type of emergency. In six out of seven cases, the pilot made high amplitude, oscillatory sidestick inputs in close proximity to the ground; in five cases, the pilot made nose down sidestick inputs when they should have been raising the nose for touchdown (or “flaring,” which will be discussed extensively in Part 5); in four cases, the aircraft crossed the runway threshold well below the correct height of 50 feet; and various cases featured long landings, bounced landings with multiple touchdowns, and other issues. But most notably, in all seven cases the crew failed to re-trim the horizontal stabilizer to match the desired path angle and speed, forcing the pilot to make continuous pitch inputs using the sidestick in order to maintain the glide path during approach. The technical term for this condition is “out of trim.” In fact, the more out-of-trim the stabilizer was, the greater the amplitude of the pilot’s oscillatory control inputs. These incidents contradicted UAC’s assumption that pilots would draw on their prior experience in conventional aircraft in order to correctly trim the stabilizer in Direct Mode.</p><p>An investigation into this pattern of incidents would have revealed that UAC’s assumptions were faulty and that a reversion to Direct Mode would manifest as a more serious failure than originally anticipated. Such an investigation could also have led to recommendations that would improve pilot training and potentially even aircraft design. However, out of the aforementioned seven incidents, two were not subject to any formal investigation at all. The remaining five incidents were investigated by the Russian Federal Air Transport Agency, Rosaviatsiya; the MAK only becomes involved if authorities categorize the event as an “accident.” But in none of these investigations did Rosaviatsiya mention any procedural violations by the flight crew, nor was there any analysis whatsoever of the pilots’ handling difficulties, and no relevant recommendations were made. In its own report, the MAK harshly denigrated these investigations, writing that they possessed “insufficient quality and depth.”</p><p>One of these incidents is worth covering in more detail in order to make a point about both the seriousness of the problem and the stark inadequacy of Russia’s investigations. This incident took place on September 5, 2015 on board RA-89046, an Aeroflot SSJ-100; the flight number, route, and number of passengers were not disclosed. According to flight data reviewed by the MAK, the aircraft was in cruise flight at 34,000 feet when an unspecified malfunction occurred and the control system suddenly reverted to Direct Mode. The pilots’ initial reaction was disorganized and they did not take manual control until after the plane had lost 500 feet of altitude. Thereafter, they focused mainly on trying to maintain altitude using the sidestick. They reset the stabilizer to 1.8˚ nose up in an attempt to re-trim the aircraft, but this value was too high, causing an out of trim situation that persisted throughout most of the flight. Because of the high trim setting, the aircraft wanted to pitch up, so the pilot countered this tendency by pushing forward on the sidestick to lower the nose, as they would in Normal Mode. But because the trim had not been reset, the tendency to pitch up simply returned as soon as the pilot released the sidestick to neutral, and the cycle would repeat, over and over and over.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BEqtEDwjaQOkvnNTg5r15A.png" /><figcaption>Flight data from the incident involving RA-89046, showing the first approach and go-around. From top to bottom: Red — normal acceleration (G’s); Brown — left sidestick deflection in pitch (positive = forward, negative = backward); Blue — right sidestick in pitch; Dark blue — pitch angle; Light blue/pink — right and left engine power lever position; Green — glideslope deviation (dots); Gray/Teal/Maroon — glideslope deviation 1 dot, glideslope deviation 0.5 dot, glideslope itself; Red — vertical profile of the flight; Purple — ground speed; Red: — calibrated airspeed; Green — target airspeed. (MAK)</figcaption></figure><p>As the flight crew attempted to approach an airport for an emergency landing, the pilot’s battle against the incorrect trim setting and against their own exaggerated inputs escalated into a dangerous rollercoaster ride. The pitch angle varied between 6.7˚ nose up and 4.4˚ nose down, with bank angles oscillating between 20˚ left and 37˚ right. The aircraft deviated from the approach centerline and fell below the glidepath, triggering an aural “GLIDESLOPE” warning from the ground proximity warning system, or GPWS. At multiple points, the “DUAL INPUT” warning also sounded, indicating that both pilots were attempting to move their sidesticks at the same time.</p><p>At 380 feet above the ground, the plane was sinking so quickly that the GPWS called out, “PULL UP.” The pilots responded by initiating a go-around. But during the go-around they temporarily lost control of the airplane, dropping from 750 to 500 feet while the GPWS frantically called out “DON’T SINK” and “PULL UP.”</p><p>After recovering from this heart-stopping plunge, the pilots lined the plane up for a second approach, which was also wildly unstable with large changes in pitch and bank angle, much like the first. Serious deviations from both the approach centerline and the glide path were observed, and the DUAL INPUT warning sounded repeatedly. On touchdown, the plane landed hard and bounced off the runway twice, but the pilots regained control after deploying the ground spoilers to break up the lift from the wings, and the aircraft rolled safely to a stop.</p><p>Despite the seriousness of the event, Rosaviatsiya did not categorize it as an incident and no investigation was conducted. No analysis of the incident is known to have taken place until after the crash of flight 1492, when the MAK asked Aeroflot to hand over flight data from previous Direct Mode reversion events. I want to go on the record to say that failing to investigate an event of this caliber is completely unacceptable and represents not only an abject failure to safeguard the flying public, but also a missed opportunity to make safety improvements that may very well have prevented the crash of Aeroflot flight 1492.</p><p>◊◊◊</p><p>Against the background of these incidents, and the still unaddressed problem of frequent Direct Mode reversions, the future pilots of flight 1492 progressed unsteadily through their training. I’ve already explained why the training itself was seriously flawed, but this isn’t a story of two perfectly competent pilots who were failed by the system. On the contrary, their piloting skills — especially Yevdokimov’s — were rather weak from the start, and the training program did not adequately address this.</p><p>First Officer Kuznetsov was, on balance, probably an average pilot for his experience level. Instructors had left various comments on his record to indicate what areas needed improvement, including maintaining the glide path, crosswind landings, windshear encounters, flaring and touchdown, and some others. But the same comment was never repeated twice, which is a good sign — it means that the trainee is learning and that weaknesses are being corrected as soon as they’re identified. Because Kuznetsov was shunted around to so many different instructors, it’s hard to be 100% sure that this record represented constant improvement, but there’s certainly no indication that he struggled to incorporate the techniques he was taught.</p><p>By contrast, Captain Yevdokimov’s records contained multiple comments about failure to maintain airspeed on approach, loss of airspeed at flare, lack of attention to approach stabilization, lack of attention to wind, poorly timed or improperly conducted briefings, late detection of windshear, making decisions without consulting the first officer, failure to make standard callouts, and various other instances of procedural non-compliance. Many of these issues were mentioned multiple times throughout his record, indicating a lack of improvement as the training program progressed. In fact, records show that he had to undergo extra training: on two occasions, he was switched to a more comprehensive track meant for less experienced pilots, and he was given exercises above and beyond the minimum required. Nevertheless, his difficulties persisted all the way through his release onto the line. He was subsequently selected for training to become an instructor despite these deficiencies.</p><p>A properly functioning safety management system, or SMS, should have flagged Yevdokimov’s difficulties and applied more training resources until his deficiencies were verifiably corrected. Because that didn’t happen, the MAK called into question the effectiveness of Aeroflot’s SMS.</p><p>In fact, the SMS was proving actively detrimental in some areas. For instance, the flight data monitoring system had been set up to generate a report if a pilot failed to apply at least 50% forward sidestick during the takeoff roll to keep the nose on the ground until reaching rotation speed, because insufficient forward pressure could cause the nose to rise before the plane has built up enough speed to lift off, extending the takeoff roll. Pilots knew about this limitation, but because they had no way to accurately determine whether the sidestick was at, say, 49% of travel vs. 51%, they had developed a practice of pushing the sidestick fully forward to the stop during the takeoff roll just to be safe. This habit led to increased wear and tear on the nose gear and could cause unfavorable pilot-induced oscillations (see Part 5) if the plane hit a pothole. But Aeroflot did nothing to correct this issue, nor did they assess why their SMS design was promoting negative habits among SSJ pilots.</p><p>◊◊◊</p><p>By now, I’ve painted a stark picture of the situation as it stood immediately before the ill-fated flight. An aircraft plagued by technical issues was experiencing dozens of times more reversions to Direct Mode than predicted. UAC did not take adequate action to resolve the recurring faults, and Aeroflot did not provide adequate training on flight Direct Mode. Deficiencies in Aeroflot’s overall training program failed to ensure that pilots developed the basic piloting skills they would need to handle this type of emergency. In-service events showed that pilots were struggling to control the SSJ-100 in Direct Mode, but Russian authorities failed to investigate these occurrences and issue appropriate safety recommendations. And then, against this background, Aeroflot flight 1492 flew into a thunderstorm with a below average captain in charge and an inexperienced first officer at the controls. What happened next was in some respects extraordinary, but for the most part, it was utterly predictable.</p><p>◊◊◊</p><h3>Part 4: Chaos in the Air</h3><p>Lightning is a threat that aerospace engineers take extremely seriously, but which may be overestimated by the average member of the flying public. Airliners are exceptionally well hardened against lightning effects, and have been since a handful of accidents in the 1960s and 1970s in which lightning strikes ignited fuel vapors inside half-empty fuel tanks, causing the aircraft to explode. Thanks to those early developments, lightning today is practically a non-issue. The average airplane will be hit by lightning numerous times during its service life, and only in vanishingly rare instances does a lightning strike cause damage sufficient to warrant even a precautionary landing.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/571/0*9-zLvh22y9rxx6gw.png" /><figcaption>An airplane is hit by lightning near Vancouver Airport in Canada. (Ethan West)</figcaption></figure><p>Certification regulations require that any safety-critical electrical and electronic components be resistant to lightning effects. In practice, most components that don’t fall under this regulation are also designed with some degree of lightning resistance too. Even so, these design requirements are largely precautionary, as lightning should pass harmlessly through the metal airframe in almost all cases. That’s exactly what happened in all previous known SSJ-100 lightning encounters.</p><p>But the 5th of May 2019 was that one-in-ten-thousand case.</p><p>As Aeroflot flight 1492 was climbing through 8,645 feet inside the leading edge of the thunderstorm, lightning struck the plane with an immense but brief burst of electrical energy. Among many other components, this energy passed through №1 VHF radio antenna, frying it instantly. Traces of lightning exposure were also found on the traffic collision avoidance system antenna, the right temperature sensor, and the right ice detector. But more importantly, it also somehow affected the plane’s two Electronic Interface Units, or EIUs.</p><p>As far as I have been able to tell, the Electronic Interface Units — erroneously referred to as Engine Interface Units in the official English translation of the SSJ FCOM — are an obscure pair of computers that translate data between formats on behalf of a wide variety of aircraft systems. These systems include the fly-by-wire system, for which it reformats data from the air data computers (ADCs) into a protocol that the primary flight controls units (PFCUs) and other aircraft systems can actually use. I wasn’t able to find any equivalent device in the Airbus fly-by-wire system, so I assume that on Airbus aircraft this function is either performed by the air data inertial reference units (ADIRUs, equivalent to the combined ADCs and IRSes on the SSJ) or it’s distributed between multiple computers. Anyway, the point is that these devices, and the fly-by-wire system as a whole, were not merely copy-pasted from Airbus, and new vulnerabilities may have been introduced in the process. This issue is discussed more extensively in Part 8.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*gn0sSYbeUEnMXchh-2QSMA.png" /><figcaption>An excerpt from an SSJ-100 training document describing the EIUs. (Superjet International Training Center)</figcaption></figure><p>The MAK was unable to identify the exact mechanism by which the lightning strike affected the EIUs. Lightning strikes are unpredictable; every one is different and they’re hard to study in a lab. But according to the devices’ own memory, at about 18:08 and 10 seconds the “A” channels on both independent EIUs rebooted into alternate flash memory partitions at exactly the same time. This could have been caused by transient power failures at the input points of both channels, but how this happened is essentially a mystery. The Ulyanovsk Instrument Design Bureau, which manufactured the EIUs, stated that a simultaneous reboot of both “A” channels was not a scenario they had ever envisioned or tested.</p><p>Since the EIU “A” channels are responsible for the actual conversion of data into the required output format, the ADCs were unable to transmit data to the PFCUs, and after half a second all three PFCUs detected the absence of any valid data from any of the three ADCs. Loss of signal from all three ADCs is a failure condition requiring reversion to Direct Mode, which is exactly what happened. As the fly-by-wire system transitioned into direct mode, a direct connection was established between the sidestick position sensors and the Actuator Control Electronics (ACE) units that command the control surface hydraulic actuators, bypassing the PFCUs. The reversion to direct mode also caused the loss of autotrim, yaw damping, automatic turn coordination, auto-spoilers, and autopilot, as designed.</p><p>Within the space of a few seconds, a large number of warning, caution, and advisory messages appeared on the screen of the crew alerting system, including “autopilot off,” “flight controls — Direct Mode,” “cabin pressure automatic mode fault,” “flap/slat protection fault,” “angle of attack and G load protections degraded,” “auto speed brake fault,” “Cat 1 &amp; Cat 2 approach faults,” and “flight director fault.” The flight data recorder temporarily recorded a wide range of completely false parameters, and the autopilot disconnect alarm started blaring in the cockpit. One of the flight crew uttered an interjection best translated as “wow” or “oh man.”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fpaMDDI3CLQOvt6qeOb4MA.png" /><figcaption>The messages displayed on the crew alerting system. (MAK)</figcaption></figure><p>First Officer Kuznetsov’s immediate reaction was to announce “You have control,” to which Yevdokimov replied, “I have control.” He grasped his sidestick and began making small inputs, probably in an attempt to maintain what he perceived to be the current flight path.</p><p>“Shall we request a return?” Kuznetsov asked.</p><p>Yevdokimov instinctively replied, “No,” but it only took one second for him to change his mind. “Yes, we will return,” he said.</p><p>Seconds later, the EIUs finished the reboot process, and all parameters became valid again. The only system on the airplane that was actually damaged was VHF radio 1. But UAC had designed the SSJ without the capability to restore the flight control system to Normal Mode in the air (more on that in Part 8). Initializing the flight control system in Normal Mode would require the plane to maintain a very steady speed and attitude, more steady than could be reasonably expected, so UAC didn’t provide any mechanism to attempt an in-flight restoration. Such a mechanism could theoretically be designed, and in fact my research suggests that Airbus aircraft are capable of returning from Direct Law to at least Alternate Law, and separately from Alternate Law to Normal Law, in some cases, if the original failure condition is cleared, depending on the nature of the failure. However, flight 1492 was stuck in Direct Law no matter what.</p><p>At Yevdokimov’s instruction, Kuznetsov attempted to declare PAN-PAN, one step short of MAYDAY, but he received no reply. The attempt was made using the inoperative VHF radio 1, which had been tuned to the current ATC sector frequency. The SSJ had two more redundant radios, of which VHF 2 was tuned to the universal emergency frequency 121.5, while VHF 3 was configured to send and receive ACARS (Aircraft Communications Addressing and Reporting Systems) messages. Both of these radios were still working, but the pilots were not yet aware that VHF 1 had been damaged.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*V37Ds0IOr0wGutBobCJcTw.png" /><figcaption>Lightning damage to the right ice detector probe. (MAK)</figcaption></figure><p>In the absence of a reply from ATC, Captain Yevdokimov kept the plane in a climbing right turn to follow the SID, which was a reasonable decision because it kept their movements predictable while out of radio contact. But after a second attempt to declare PAN-PAN was met with silence, Yevdokimov commented, “It looks like the radio has been lost as well,” and Kuznetsov replied that he would try again on the emergency frequency. Switching to the still functional VHF radio 2, Kuznetsov announced, “Sheremetyevo Tower, Aeroflot 1492, how do you read?”</p><p>This transmission was heard by the controller, but several frequencies were simultaneously tuned at his station and he didn’t check what frequency had been used to call him. He attempted to give the crew the frequency for the next ATC sector, but he transmitted on the Approach Control frequency, which flight 1492 couldn’t hear because it was tuned in the faulty VHF 1. This same sequence of callbacks then took place again, after which the crew decided to set their transponder code to 7600, the universal signal for “radio failure.”</p><p>Seconds later, however, Kuznetsov declared PAN-PAN over the emergency frequency, which finally prompted the controller to respond on 121.5, where the crew of flight 1492 was able to hear him. Kuznetsov explained that they had lost radios and that the flight controls had reverted to Direct Mode, to which the controller replied with a clearance to begin descending to 8,000 feet for a return to the airport. Captain Yevdokimov manually put the plane into a descent and set his target altitude and speed as a guide; moments later, their altitude peaked at 10,600 feet.</p><p>When the flight controls entered Direct Mode, the horizontal stabilizer was trimmed slightly nose up for cruise flight at a speed of 250 knots with the engines at climb power. This setting was initially fairly close to the desired setting as Captain Yevdokimov continued to fly the SID, but once he initiated a descent, the original trim setting became wildly inappropriate for the flight conditions. Pilots of conventional aircraft are taught that the trim should be adjusted every time there is a significant change in airspeed, flight path angle, or configuration, and with the autotrim function unavailable, this was now Yevdokimov’s responsibility. But at no point in the minutes after the initial reversion did he adjust the trim setting. Instead, he kept trying to use his sidestick to point the nose in the direction he wanted to go, before releasing it to neutral. The incorrect trim setting would then force the nose back the other way, prompting him to make another corrective input, over and over and over — exactly like the previous case of RA-89046.</p><p>Yevdokimov’s control over the bank angle displayed similar oscillations for similar reasons. In Normal Mode, he could establish the plane in a continuous 20˚ right bank by holding his sidestick to the right until the bank angle reached 20, then letting go. But in Direct Mode, he needed to hold the sidestick to the right continuously, because if he let go, the ailerons would return to neutral and the plane would try to level out. And yet that’s exactly what he did, over and over.</p><p>It must be noted that the flight crew’s performance was negatively affected by several factors. The lightning strike and cascade of warnings were extremely startling and probably rather scary, which would have sharply increased the flight crew’s stress levels. Elevated stress tends to result in more frequent errors and procedural deviations, which was now observed not only in Yevdokimov’s failure to adjust the trim, but also in his failure to call out speed and altitude changes, engine power adjustments, and so on, whereas before the emergency he had followed these procedures almost perfectly. Similarly, as they began the descent, the controller asked whether they could use the standard frequency, but instead of tuning the Approach frequency on VHF radio 2, they simply tried again, unsuccessfully, using VHF radio 1 — a lack of creativity that may be a symptom of elevated stress.</p><p>Another symptom of high stress was a tendency by both pilots to clip transmissions, beginning in the minutes after the emergency. When Captain Yevdokimov used the interphone to inform the cabin crew that they were returning to the airport, the flight attendants had a hard time understanding him because the beginning and end of his transmissions were cut short. The crewmembers later reported that the interphone may have been malfunctioning, but the MAK found that this was actually caused by Yevdokimov beginning to speak before pressing the push-to-talk button, and releasing the button before he was done — a known sign of elevated stress.</p><p>At the same time, many of First Officer Kuznetsov’s transmissions to ATC were similarly clipped or even entirely absent after the first word. When the controller failed to hear them, the pilots took this as evidence that none of their radios were operating normally. But what had actually happened was that Kuznetsov was not using his push-to-talk button because it was located on his sidestick and he didn’t want to make inadvertent inputs while Yevdokimov was flying manually. Instead, he was using the INT/RAD switch on the radio control panel. This spring-loaded switch defaults to the INT setting, for intercom, which causes the pilots’ own voices to be broadcast through each other’s headsets to ease communication in the noisy cockpit. The pilot can also move this switch to the RAD setting to transmit over the radio without using the push-to-talk button, but the switch must be held in the RAD position throughout the entire transmission or it will spring back into the INT position and the message will be cut short. The MAK determined that the actual reason for Kuznetsov’s clipped transmissions was that, in a state of elevated stress, he kept forgetting to hold the switch down while he was talking.</p><p>Between the perceived difficulties with VHF radio 2 and Captain Yevdokimov’s difficulty maintaining the desired flight path, the pilots began to get the impression that the emergency was much more serious than it actually was. This perception would soon begin to exert a negative influence on the pilots’ decision-making.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*FGci4eu_M6OFnt9g-pvy-Q.png" /><figcaption>Flight parameters from 18:07 to 18:09. The moment of the lighning strike is shown by the light blue vertical line. Putting the translations of every single parameter into this image is impractical but if you aren’t sure what one of these parameters represents and you want to know, shoot me a message. (MAK)</figcaption></figure><p>As Yevdokimov steered the plane into a descending right turn to position himself for approach, he instructed Kuznetsov to read the Quick Reference Handbook (QRH) section on Direct Mode. Noting that the “autopilot off” warning held a higher priority on the crew alerting system display, he decided to start with the QRH checklist for an uncommanded autopilot disconnect instead, which simply called for him to test whether the autopilot could be re-engaged. He immediately discovered that it would not.</p><p>At that moment the controller called to ask if they needed assistance from emergency services after landing, to which the crew replied, “No, so far everything is fine.” On the basis of this transmission, controllers decided not to instruct fire crews to pre-position the fire trucks. This decision belied the danger that the crew actually felt they were in.</p><p>Captain Yevdokimov now again ordered Kuznetsov to perform the Direct Mode QRH checklist, which he began to do. But he was repeatedly interrupted by transmissions from air traffic control, which Yevdokimov ordered him to answer. This dynamic represented rather poor crew resource management, or CRM. Pilots are taught that in an emergency, the flying pilot should assume responsibility for radio communications so that the non-flying pilot can complete the emergency checklists in a timely and thorough manner. Unfortunately, that was not what happened, and the pilots’ understanding of the checklist was degraded as a result. In fact, when he finally got a chance, Kuznetsov simply read the words on the page as fast as he could:</p><p><em>“ Autothrottle do not use, maneuver with care. Trim manually. Speed brake, use no more than 1/2. For landing use Flaps 3. TAWS, landing gear, Flaps 3 on. Approach speed, V reference plus 10. Landing distance multiply by 1.34. Speed brake set manually FULL at landing. Go-around thrust levers set manually NTO.</em>”</p><p>His tone of voice betrayed no interest in the contents of what he was reading, and the pilots never discussed any of the items. It was as though the checklist was a formality to get out of the way. And despite the checklist’s reminder to “trim manually,” Yevdokimov continued to leave the trim setting right where it had been ever since the lightning strike.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4rvZyZmMndiVpfldXOHeZA.png" /><figcaption>Aeroflot’s QRH section on flight in Direct Mode. (MAK)</figcaption></figure><p>Before Kuznetsov could read any more of the checklist, the controller instructed them to fly heading 210 to intercept the localizer for runway 24 Left. The localizer is part of the instrument landing system, or ILS; it helps the pilot or autopilot keep the plane aligned with the runway centerline. But it was too early to maneuver for the approach at this point, because their altitude was too high and they weren’t done with all the emergency checklists. So Yevdokimov said, “We should go into a circuit. We are not ready for approach.” Kuznetsov requested as much from the controller, who gave them a heading that would reverse their course. Yevdokimov then had a better idea, prompting him to jump on radio himself, where he asked, “Aeroflot 1492, a holding pattern over Kilo November, if possible.”</p><p>This decision was one of the best Yevdokimov had made so far. The aircraft was not in danger and there was no point rushing into an approach without preparing for it. The crew could have circled in a holding pattern while they figured out what was wrong with their plane, why it was flying funny, and how they would stabilize the approach. But sadly, that isn’t what happened. In an unfortunate coincidence, Yevdokimov’s request overlapped with a transmission from another aircraft on the standard frequency and the controller never heard it. Despite this, Yevdokimov never repeated his request for a holding pattern around the KN radio beacon, and the flight never entered a proper hold, completing only a single 360-degree orbit.</p><p>As Yevdokimov hand-flew the plane into the orbit, he struggled to maintain a stable flight path. Their bank angle varied significantly, reaching values as high as 40 degrees to the right — above the normal maximum — and he was unable to maintain their cleared altitude of 600 meters (2,000 ft). The altitude alerting system kept going off to warn that they were deviating from the crew-selected target altitude by more than 200 ft (60 m), prompting Yevdokimov to explain, “What’s wrong? Plus, minus 200 feet?” But he didn’t interrogate why he was unable to hold a steady altitude.</p><p>In fact, every time he leveled the wings, he pitched up too much, causing the plane to climb, and every time he turned, he didn’t pitch up enough to compensate for the decreased lift in a high bank angle, causing the plane to descend. In other words, every time he tried to focus on bank, he would lose control of pitch, and vice versa. One of the reasons for this difficulty, other than the incorrect trim setting, was the lack of automatic turn coordination and Yevdokimov’s failure to coordinate his turns manually using the rudder, which caused a significant drag-inducing sideslip every time he tried to bank.</p><p>While Yevdokimov muddled his way through the orbit, Kuznetsov observed that they would land over their maximum landing weight due to their nearly full fuel load, and asked whether they should complete the overweight landing checklist. Yevdokimov instructed him to do so, but neither pilot proposed holding for a while to burn off fuel, which would have been safer, as the SSJ — like almost all narrow body jets — does not have fuel dumping capability.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*UddDaeca25jeRPQLiFHkUA.png" /><figcaption>The path of flight 1492 after time 18:10. Add three hours to the image for local time. (MAK)</figcaption></figure><p>Coming around the back of the orbit, the crew began to configure for landing, starting with extending the flaps to position 1. As the flaps came out, remarkably, Yevdokimov manually repositioned the trim nose up to compensate — the first time he had done so in the 13 minutes and 30 seconds since the reversion to Direct Mode. In the MAK’s view, somewhere during his training Yevdokimov most likely received the false impression that in Direct Mode he only needed to re-trim the aircraft during a configuration change, when actually any significant change to airspeed or flight path angle also requires a corresponding adjustment. But because Aeroflot’s instructor staff stonewalled the MAK, the cause of such a mistaken impression could not be confirmed. All we know for sure is that he flew the aircraft out of trim for a considerable period, requiring constant sidestick inputs, but didn’t attempt to trim until the flaps were extended — which almost certainly wasn’t a coincidence.</p><p>Over the next minute, the controller provided them with vectors to intercept the localizer, while the pilots began reducing their airspeed, set the flaps to position 2, and extended the landing gear. Captain Yevdokimov then adjusted the trim one more time, to 3.5˚ nose up; this would be the last time he touched it.</p><p>By this point, an intriguing feature of Yevdokimov’s flying had clearly presented itself — namely, a bizarre tendency to press the sidestick priority button for no obvious reason. The purpose of this button is to lock out the opposite sidestick in case it jams or malfunctions. But flight data showed that at no point did the first officer’s sidestick move; in fact, Kuznetsov took care not to touch it. So why was he doing this? In the MAK’s opinion, the answer lay in Yevdokimov’s previous experience on the Boeing 737 and Ilyushin Il-76, both of which require manual trim when the autopilot is off. On those aircraft, the trim switches on the captain’s side are located on the left-hand part of the yoke and can be easily actuated using the left thumb — coincidentally, the exact same location and motion as the sidestick priority button on the captain’s left-mounted sidestick. It was therefore quite possible that when he perceived that the aircraft was fighting his pitch inputs, Yevdokimov’s muscle memory from his previous aircraft kicked in. That’s not to say that he genuinely thought he was trimming the aircraft by pressing the sidestick priority button; in fact, he clearly knew where the trim switches were because he used them four times while the flaps were being extended. Rather, in a moment of elevated stress, his body reacted in the way it remembered without his brain necessarily being in the loop.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*EA4DLgHr6kwIot41injKAA.png" /></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*B3X8_tI7Uf-OUJaMiL2m6w.png" /><figcaption>Top: The location of the trim switches on the B737. Bottom: the location of the sidestick priority button on the SSJ-100. (MAK)</figcaption></figure><p>It’s also worth mentioning that on the SSJ, the manual trim control switches are located on a separate control panel, requiring the pilot to remove their hand from the thrust levers, find the switches — which might never be used in an SSJ pilot’s career, outside of training — and then depress them. This helps explain why Yevdokimov only adjusted the trim when prompted to do so by a conscious configuration change. On a conventional aircraft, most trimming is instinctive in response to feedback forces without any need to engage executive function.</p><p>In his post-accident interview, Yevdokimov told the MAK that the nose kept dipping despite his attempts to re-trim the stabilizer. Most probably this statement was made to explain the flight data, which was already known to him by the time of the interview, rather than a genuine recounting of what he felt during the flight. It does not appear that he consciously connected the trim setting to his control difficulties at any point prior to the accident.</p><p>◊◊◊</p><p>At 18:24, flight 1492 began its turn onto final approach. At that time, the pilots set the spoiler handle to “ground spoilers armed,” which is a normal part of the approach configuration. In Normal Mode, this setting will cause the spoilers to deploy automatically on touchdown, spoiling the lift from the wings and pushing the plane into the runway. This improves braking action and prevents the plane from bouncing off the runway surface. But in Direct Mode, automatic spoiler deployment is unavailable, so why did they arm the spoilers anyway? In their interviews, the pilots explained that they armed the spoilers to prevent an automated alert from being generated at 1,000 feet on approach if they were not in the landing configuration. While this logic is valid, arming the spoilers for an automatic deployment that can’t happen is potentially misleading, in that it degrades the pilots’ awareness of the need to deploy the spoilers manually, an activity that they never have to perform during normal flight. The crew should have compensated by briefing who would deploy the spoilers and when, but they did not. This issue would ultimately have serious consequences for the outcome of flight 1492.</p><p>In any case, the primary task now facing the pilots was to fly an ILS approach to runway 24 Left at Sheremetyevo without the use of the autopilot or flight director. Normally, the autopilot automatically tracks the localizer signal to align with the runway and the glideslope signal to achieve the correct descent gradient. Alternatively, if the autopilot is off, the flight director will display the real-time control inputs required to follow those signals. But in Direct Mode, neither of these features was available, forcing the crew to fly the approach by what’s known as “raw data.”* In a raw data ILS approach, the pilot refers to crude deviation indicators that display the aircraft’s position relative to the localizer and glideslope in terms of “dots.” The more dots there are between the aircraft position indicator and the line representing the signal, the greater the actual distance between them. Following the ILS using these dots is harder than following a flight director and is not normally done during routine operations.</p><blockquote>*It is worth noting that on the Airbus, the flight director is available in Alternate Law. This is one of the drawbacks of the SSJ’s lack of an equivalent to Alternate law.</blockquote><p>When Captain Yevdokimov first attempted to roll out onto the localizer, he discovered that he was much too far to the right, prompting him to correct. The deviation was large enough that the Approach controller noticed too, and he transmitted, “Aeroflot 1492, if you are planning to capture the localizer, you should proceed to the left about 20 degrees.” Kuznetsov acknowledged, although Yevdokimov was already trying to correct, and the aircraft was slowly converging with the localizer. Kuznetsov then set the flaps to position 3, which was the prescribed landing position in Direct Mode.</p><p>At 18:26, the approach controller handed flight 1492 over to the tower controller. At the same time, the pilots changed their transponder code from 7600 (“radio failure”) to 7700 (“general emergency”) without informing the controller. The controller didn’t notice this change because flight 1492 was already highlighted as an emergency aircraft on his radar display. Had the controller noticed this change, or had the flight crew reported an emergency, the fire trucks would have been pre-positioned for the landing. But this never happened, and in fact the pilots never informed the cabin crew or passengers to brace for an emergency landing either.</p><p>Moments later, at 18:27, flight 1492 intercepted the glideslope and Yevdokimov initiated the final descent. This was done without completing the approach checklist or the approach briefing, eliminating an opportunity for the crew to review the differences between a normal approach and a Direct Mode approach. Given that the pilots totally glazed over the instructions for Direct Mode flight in the QRH, it’s unlikely that they fully understood what was required of them. The decision to approach without having completed these items represented poor judgment, as well as poor crew resource management. In fact, Yevdokimov had decided they were ready for an approach without asking Kuznetsov — who was in charge of reading the checklists — whether <em>he</em> was ready too. For his part, Kuznetsov did not challenge Yevdokimov’s decision.</p><p>In hindsight, it’s very likely that Yevdokimov began the approach as quickly as possible because he felt that the airplane was not flying normally. This is the correct course of action when a dangerous situation exists, but the pilots had not attempted to diagnose the cause of their difficulties. Had they done so, they would have understood that the flight was not in danger, and they might not have rushed unprepared into a challenging approach that required multiple non-standard actions.</p><p>It’s also highly noteworthy that the flight crew never set the go-around altitude on their altimeters to provide an easy reference point in the event of a go-around. This step is part of the approach checklist that was not completed. Its omission further testifies to Yevdokimov’s strong and growing desire to land without making a risk assessment or establishing a contingency plan.</p><p>During the descent, the airspeed was kept quite close to the 155-knot approach speed calculated and set by the crew, but the aircraft was almost continuously half a dot below the glideslope. Furthermore, the aircraft was not trimmed for a descent in the landing configuration, and Yevdokimov had to apply continuous back pressure using the sidestick to prevent the nose from dropping too low. And yet no attempt to adjust the trim setting was made.</p><p>To make matters worse, the thunderstorms were by now approaching the airport vicinity, and flight 1492 was fighting a 30-knot wind out of the south-southwest, resulting in a crosswind component that had to be counteracted with an 8-degree left sideslip. But when the tower controller called them just before 18:28 to issue landing clearance, he also informed the crew that the wind over the runway was out of the south-southeast at 13 to 19 knots. The difference between the reported wind over the runway and the wind they were encountering on approach implied that the flight would encounter windshear during the final part of the descent. As the approach was aligned along a southwesterly heading of 240˚, a wind shift from strong southwesterly to weaker southeasterly would decrease the headwind component and cause a noticeable reduction in aircraft performance. A headwind tends to increase airspeed, so if the headwind goes away, airspeed will decrease, which means that lift will also decrease and the plane will descend faster — not what you want in close proximity to the ground.</p><p>Indeed, just 30 seconds later, as flight 1492 descended through 1,100 feet above airport level, the on-board weather radar detected an impending change in wind speed and direction and triggered an automated warning callout: “GO AROUND, WINDSHEAR AHEAD.”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/748/0*1JXM77JEHB8sxVfX.png" /><figcaption>The effect of decreasing headwind/increasing tailwind windshear during an approach to landing. (World Meteorological Organization)</figcaption></figure><p>According to the QRH, the pilots must react to this warning by executing a go-around immediately, unless it can be clearly established that windshear is not a threat. Captain Yevdokimov later stated that he chose to ignore the warning on this basis. Notably, the QRH did not provide any criteria to be used when making this determination, which the MAK identified as a problem. But a bigger problem was that with a thunderstorm approaching the airport, the pilots had every reason to believe that the windshear warning was genuine, and in fact it was. Yevdokimov’s kneejerk reaction to continue represented further evidence that he was “tunneling in” on the goal of landing, causing him to instinctively disregard information that supported a different course of action.</p><p>Even more worrying, though, was Yevdokimov’s stated justification for determining that the windshear was not a threat. In his mind, he told the MAK, it was permissible to continue because the aircraft met the stabilized approach criteria: landing configuration, aligned with localizer and glideslope, at the correct speed, with the correct thrust lever position, and no major inputs required to land in the touchdown zone. Therefore, he said, the plane was not encountering windshear. But that’s a misunderstanding of how the predictive windshear warning works — it doesn’t say “you’re in windshear right now,” it says “windshear AHEAD.” The fact that the approach is stabilized <em>now</em> has absolutely no bearing on whether there is windshear ahead.</p><p>If there was any question about where Yevdokimov got this dangerously mistaken impression, it was dispelled in Aeroflot’s dissenting opinion, attached to the MAK report. Incomprehensibly, Aeroflot took Yevdokimov’s side on this issue and wrote that he was within his rights to ignore a <em>predictive </em>windshear warning if the aircraft was not <em>presently experiencing</em> windshear effects. This is, without exaggeration, the stupidest stand I’ve ever seen an airline make during a crash investigation. Aeroflot’s position on this issue isn’t merely wrong, it’s wildly unsafe and recklessly endangers lives for no justifiable reason.</p><p>In any case, right as the windshear warning ceased, the aircraft descended through 1,000 feet above airport level, where Aeroflot procedures required that the aircraft be stabilized for approach. Since all the stabilization criteria were technically met, other than the persistent half-dot deviation below the glideslope, Yevdokimov announced that they would continue. Kuznetsov acknowledged, then reminded Yevdokimov that the maximum vertical speed at touchdown in their overweight condition was 360 feet per minute.</p><p>At 18:29, at a height of 270 feet, Kuznetsov called out that they were at minimums, and Yevdokimov announced “runway in sight.” But at almost that same moment, the plane entered the windshear zone, and the headwind component started decreasing toward zero. As this occurred, the plane rapidly fell even farther below the glideslope, triggering a synthetic “GLIDESLOPE” callout from the ground proximity warning system. But as Yevdokimov later explained, he descended below the glideslope on purpose in order to get down early, assume a shallower approach angle, and soften the touchdown. This is a somewhat common airman’s myth that I’ve seen before — this idea that flying below the glideslope just before landing can prevent a hard touchdown or increase the usable runway length. The truth is that adhering to the stabilized approach criteria already provides adequate protection against these issues, even if the airplane is overweight.</p><p>In response to the GLIDESLOPE warning, Yevdokimov called out “Informative,” citing the Aeroflot operations manual, which stated that below decision height, with the runway in sight, a GLIDESLOPE warning is purely informative and does not require the crew to execute a go-around. This provision was not in line with Sukhoi’s FCOM, which stated that any warning or failure, other than engine failure, between 1,000 and 100 feet on final approach requires a go-around. However, the QRH — also a Sukhoi product — states that the correct response to a GLIDESLOPE warning is to re-establish the plane on the glideslope. These contradictory provisions may have caused Aeroflot crews to habitually ignore GPWS glideslope callouts.</p><p>After the GLIDESLOPE warning, First Officer Kuznetsov started rapidly calling out their vertical speed, which at that point was slightly high. To make their descent profile shallower, as he had intended, Yevdokimov increased engine power, causing their speed to increase substantially above the approach reference speed of 155 knots. But this didn’t arrest their sink rate as much as it should have because of the ongoing windshear, and the plane continued to descend at a rate of up to 800 feet per minute as it neared the runway threshold. Moments later, flight 1492 crossed the runway threshold at a height of 33 feet, well below the normal 50 feet, and dropping fast.</p><p>It was here, in this critical moment, that a rapid sequence of events took place that would turn this story into a tragedy.</p><p>◊◊◊</p><h3><strong>Part 5: A Flare for Drama</strong></h3><p>The seconds immediately before, during, and after touchdown require more raw piloting skill than any other phase of flight. Causing an aircraft weighing dozens or hundreds of tons and traveling at over 150 km/h to contact the ground in a controlled and comfortable manner isn’t easy and doesn’t come naturally. Pilots practice extensively in order to learn how to get the touchdown just right, and for any given aircraft type you’ll find experienced pilots espousing various techniques without complete agreement.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/878/0*MWkrsFNCw7pUzIGJ.png" /><figcaption>An example of flaring for landing. (Boeing)</figcaption></figure><p>The first stage of this process is to “flare” the aircraft by raising the nose. This reduces the descent rate, ideally to near zero right at the moment of touchdown, while positioning the plane to land on its main landing gear first. The exact height at which the pilot must begin the flare depends on who you ask, but generally this occurs within the last five seconds before touchdown. Starting the flare too early can cause the plane to float down the runway or not touch down at all, while flaring too late can lead to a hard landing. The aircraft’s airspeed over the threshold can also influence the optimal flare initiation point, as will the descent rate. Some advanced autopilots can flare the aircraft automatically, but on most aircraft types this is done manually even if automatic landing is available. The SSJ-100 FCOM advised pilots to initiate the flare with one continuous motion, hold the sidestick “in the required position,” and do not permit “forward sidestick movement” after the flare has begun.</p><p>On Airbus aircraft, there is a Normal Law sub-mode called Flare Law that kicks in when the aircraft descends below 50 feet radio height in the landing configuration in order to make the plane feel more like a conventional aircraft. Normally, the constant readjustment of the stabilizer trim to match the commanded pitch angle would make it too easy to overcontrol the aircraft during this sensitive phase of flight, so in Flare Law the trim is frozen at its last position before the pilot initiates the flare. At the same time, Flare Law commands a slight nose down pitch, about -2˚, which together with the frozen trim setting prevents the nose up moment from becoming excessive by essentially mimicking the force feedback from a conventional aircraft.</p><p>The SSJ doesn’t have a Flare Law, although it does still freeze the trim setting at 50 feet, just like the Airbus, and modifies the relationship between the sidestick and the elevators to reduce the risk of overcontrol. The differences between these features and a fully-fledged Flare Law seem to be mostly semantic rather than practical. However, it’s worth pointing out that there’s relatively little difference in pitch behavior below 50 feet, whether the SSJ is in Normal Mode or Direct Mode. In both modes, the trim is not automatically adjusted and elevator deflection is at least relatively proportional to sidestick deflection. However, certain systematic differences between the two modes do come into play.</p><p>Before we can understand what happened during the last moments of flight 1492, we have to talk about some of those differences, as well as the way Captain Yevdokimov perceived them. In his interviews, Yevdokimov stated that the controls were less responsive than normal and the plane seemed slow to react to his inputs. However, the control response in Direct Mode is actually about a tenth of a second faster than in Normal Mode because the signal doesn’t have to be processed by the PFCUs. In fact, the MAK verified that the control response on flight 1492 was in line with the manufacturer’s model and was not slower than in Normal Mode. There were two reasons Yevdokimov developed this false impression: first, due to the lack of control adjustment for airspeed in Direct Mode, larger inputs would have been needed to produce the same aircraft response as the plane slowed for landing; and second, because the airplane was out of trim, his inputs had to overcome the force of the incorrect trim setting before the desired attitude could be achieved.</p><p>Because of these factors, Yevdokimov slowly taught himself to make larger and larger inputs over the course of the flight, and displayed less and less hesitation in doing so. But as his inputs got bigger and faster, he ran up against the fact that the elevator control actuators can only move so fast. With no direct cable connection between the sidestick and the controls, and no force feedback, it’s possible to jerk the sidestick faster than the elevators can respond. Normally this isn’t an issue because moving the sidestick so far, so quickly is crazy outside of certain extreme emergencies. But it now became an issue because whenever Yevdokimov rapidly moved the sidestick, the elevator deflection was limited by the rate of actuator travel, creating a perception that further inputs were needed. The aircraft would then catch up to his inputs, and because he was commanding the maximum elevator travel rate, the rate of pitch change would increase more rapidly than he was expecting. This is also at least partly because Normal Mode has an artificial pitch rate limit, whereas in Direct Mode the limit is mechanical. Furthermore, due to the lack of damping, the maximum deflection available is slightly higher than in Normal Mode. Due to these factors, Yevdokimov would respond to the high pitch rate with an opposite input proportional to the perceived excess, causing the cycle to reverse direction. This is a phenomenon known as “pilot-induced oscillation,” or PIO.</p><p>If a PIO event becomes <em>divergent</em>, with the magnitude of each input exceeding the previous, then devastating results can follow. A divergent PIO event is also known as “adverse aircraft-pilot coupling,” or APC, in which pilot inputs quickly reach the mechanical control limits. Such a situation can arise when some aircraft parameter crosses a threshold value and provokes a large pilot reaction due to a difference between actual and expected aircraft response.</p><p>Pilot-induced oscillations can occur on any aircraft in any control law, but they are somewhat more common on fly-by-wire aircraft without force feedback, especially when there is a direct relationship between sidestick position and control surface deflection. Similar oscillations were observed in all of the previous Direct Mode reversion events analyzed by the MAK, especially during final approach. There appears to have been a systemic failure to train SSJ pilots on strategies to avoid PIOs in Direct Mode. However, this was a problem that extended to Normal Mode as well, as evidenced by recovered data from Captain Yevdokimov’s last 37 landings before the accident. In each of these landings, he made oscillatory pitch inputs at low altitude, and during flare he pulled up excessively, in some cases using nearly full nose up sidestick travel. Sometimes this resulted in over-flaring and a long or floated landing; other times, he made a nose down input to correct for his own excessive pitch up, causing touchdown to occur with a significant nose down pitch rate. In some cases this resulted in a bounce off the runway, which is undesirable, for reasons we’ll get into shortly.</p><p>Data from flight 1492 show that an oscillation was occurring during the last minutes of the flight, as Yevdokimov moved the sidestick rapidly forward and back with a periodicity of about two seconds. He was not consciously aware that his inputs were self-oscillatory; rather, he believed that he was doing his best to keep the plane on the desired trajectory, and that something was interfering with his ability to do so. At this stage the oscillations were not divergent; that is to say, each was about the same size as the last, and full control authority was not used. But that was about to change.</p><p>As flight 1492 crossed the threshold, Captain Yevdokimov’s substantial increase in engine power caused a large increase in airspeed, reaching a peak of 173 knots, 18 knots above the approach reference speed. At most airlines, a speed greater than ten knots above the approach reference speed indicates an unstable approach and may warrant a go-around. However, Aeroflot’s stabilized approach criteria allowed a deviation up to +20 knots above the reference speed, which the MAK pointed out is unusual, unsafe, and may encourage pilots to continue flawed approaches. This likely played no direct role in Yevdokimov’s decision-making because he was committed to landing no matter what, but it certainly wasn’t helping to foster a cautious attitude.</p><p>Regardless of why Yevdokimov allowed this high speed to develop, its primary effect was to increase the responsiveness of the aircraft to pilot inputs. At the same time, their descent rate was increasing due to the windshear, but the pitch angle was higher than usual because Yevdokimov was deliberately approaching the threshold with a shallower flight path angle. At the moment of the flare, these factors combined to turn what had been a stable oscillation into a divergent one.</p><p>After crossing the runway threshold, Yevdokimov reduced thrust to idle at a height of 17 feet, then initiated the flare by pulling the sidestick back to 8.8˚ — about 65% of full travel, which is 13.7˚ in each direction. This input was similar to the inputs he had used to start the flare on previous approaches in Normal Mode. But this time, due to their high speed and higher starting pitch, the airplane responded to this input more rapidly than he was expecting. After less than one second, he attempted to slow the nose-up pitch rate by pushing forward — exactly what the FCOM says not to do. All that was needed was to return the sidestick to neutral, because the trim hadn’t been reset upward and the airplane would desire to pitch down all by itself. But instead, he pushed the sidestick to 5.8˚ forward, causing the actual pitch angle to peak at 3.8˚ before starting to reverse. As he felt the onset of this reversal, he instinctively judged that it was too large, especially with the ground rapidly approaching, so he pulled back sharply — too sharply, in fact, as the sidestick deflection reached 13.2˚ back, just short of the maximum. This caused the pitch angular rate trend to reverse again, and the pitch angle bottomed out at 1.8˚ before rapidly rising. This rise again caught Yevdokimov by surprise, and within one second he pushed the sidestick from nearly full back to a full 13.7˚ forward. Once again, the pitch attitude peaked, this time at 6.3˚ nose up, before starting to decrease rapidly. And like clockwork, as he sensed the nose about to drop, he hauled back on the sidestick so fast that it went from the forward stop to the aft stop in a quarter of a second. The elevators physically could not respond fast enough to reflect this, and for the next second the airplane continued to pitch down, dropping through neutral to -1.7˚.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qyw8VqMYiV7lzZ7EzWye5Q.png" /><figcaption>I highly recommend opening this graph in a new tab so you can follow along on this section. The chart shows data from flight 1492 below 100 feet. Translations of each parameter, from top to bottom: Dark red dots — left weight on wheels; Black dots — nose weight on wheels; Blue dots — right weight on wheels; Red/Dark red — left/right thrust lever position; Olive green/red — normal acceleration; Dark red/black: left/right sidestick position (positive = forward, negative = backward); Olive green/purple — right/left elevator position; Red — pitch angular acceleration; Teal — pitch angular rate; Blue — pitch angle; Pink — airspeed; Red — radio altitude. (MAK)</figcaption></figure><p>Yevdokimov was now in the grip of a divergent PIO event. However, because the sidestick has a nearly direct relationship with elevator position in Normal Mode below 50 feet anyway, the fact that the controls were in Direct Mode played almost no direct role in the events described in the above paragraph. Rather, if Direct Mode had any influence on these events at all, it was to accustom Yevdokimov to making excessive control inputs, as I discussed earlier. This explains why the magnitude of his inputs was so much larger on flight 1492 than on previous flights, even though the active pitch philosophy below 50 feet was essentially the same.</p><p>In any case, the pitch angle had only just begun to rise above its nadir of -1.7˚ when the plane touched down on the runway with all three landing gears almost simultaneously. The descent rate at touchdown was around 630 feet per minute (3.2 m/s), well above the desired value, due to the windshear and the low pitch attitude. Instead of easing onto the runway in a nice, almost asymptotic curve, the plane simply bounced off like a hurled stone, pulling 2.55 G’s in the process.</p><p>◊◊◊</p><p>All airline pilots are taught strategies for avoiding, and recovering from, a bounced landing; in fact, such training is mandatory in Russia. That’s because bounced landings draw pilots into a psychological trap that worsens their consequences. After a plane bounces back into the air, the pilot’s instinct is to plant it back on the runway, which often results in nose-down inputs in very close proximity to the ground. These in turn cause the plane to impact a second time nose-gear-first and with a significant descent rate. The nose gear then bounces off again, pivoting the nose up and the tail down, at which point the main landing gear impacts the ground again, harder and faster this time, which in turn causes the plane to bounce even higher. In some cases, this cycle repeats until the landing gear breaks and the plane crashes. I previously wrote about a series of such accidents involving the McDonnell Douglas MD-11, which you can read about <a href="https://admiralcloudberg.medium.com/over-and-down-the-crash-of-fedex-flight-80-627e05b74fe9">here.</a></p><p>According to the SSJ FCOM, the appropriate reaction to a small bounce of less than 5 feet is to reduce thrust to idle and retain the sidestick in the position it was in at first touchdown as a strategy to counteract the desire to push forward. This should cause the plane to touch down more gently the second time. Alternatively, if the bounce is higher than five feet, the correct response is to increase power and go around. But while these procedures are alright in theory, the MAK points out that it’s not always clear to the pilot whether a bounce is higher or lower than 5 feet, or whether the situation is recoverable, and in fact no airplane has procedures that clearly address this problem.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/590/0*M4ss0Vf18ISMLlfN.jpg" /><figcaption>Recovering from a bounce, or turning the bounce into a PIO. (TSB of Canada)</figcaption></figure><p>An added complication is the role of the spoilers. In Normal Mode, the spoilers will automatically extend at first ground contact, which tends to dampen the plane’s desire to bounce. But in Direct Mode, the pilot must remember to deploy the spoilers manually as soon as the gear first touches down. In previous Direct Mode reversion events involving the SSJ, the pilots did not immediately do so, and some of these flights continued to bounce off the runway repeatedly until the pilots finally deployed the spoilers.</p><p>Unfortunately, the crew of flight 1492 did not remember to manually deploy the spoilers during the first touchdown, missing an opportunity to dampen the bounce. Yevdokimov did attempt to deploy the thrust reversers, but the reverser doors did not open because a positive weight-on-wheels signal is required to move them, and the plane was already airborne again. This first bounce was nevertheless recoverable, because the plane did not reach a height of five feet. But instead of applying the recovery maneuver described in the FCOM, Yevdokimov suddenly reversed his input from full nose up to full nose down in reaction to the large nose up moment generated by his previous input and the effect of the bounce. His new full nose down input then caused the pitch angle to peak at 4˚ before falling rapidly through neutral and into a nose down position. This prompted him to reverse his input to full nose up yet again, but it was too late. Flight 1492 now impacted the runway a second time, pitched 4.2 degrees nose down, with a vertical speed of -830 feet per minute (4.2 m/s). On impact the nose gear bounced up off the runway, the airplane pivoted about its center of mass, and the main landing gear slammed into the ground with a bone-shattering force of 5.85 G’s.</p><p>During the investigation, simulations were undertaken to determine what factors contributed to this devastating second bounce and how it might have been avoided. The findings included the following:</p><p>1. If, at the moment of touchdown, Yevdokimov had deployed the spoilers, relaxed the sidestick to neutral, and reduced thrust to idle, they would have bounced then landed hard again, pulling 3.8 G’s, but there would have been no second bounce and the plane would not have been damaged.</p><p>2. If Yevdokimov had kept the sidestick in neutral instead of pulling back sharply at 17 feet, the plane would not have bounced off the runway at all.</p><p>3. Without the effects of the windshear, the aircraft would have touched down farther along the runway, but three seconds sooner, with a slightly positive pitch angle, and a bounce still would have occurred. But because the pilot’s actions were largely reactive to the perceived aircraft state, it was impossible to say whether this would have prompted him to make inputs that might avoid further bounces.</p><p>4. If the windshear was present, the spoilers still did not deploy, and Yevdokimov made all the same inputs, but the control law was in Normal Mode, the plane would have touched down hard a second time, pulling 3.6 G’s, but would not have bounced again. This was because of the slightly slower control response and increased damping in Normal Mode, which would have coincidentally resulted in a less extreme nose down attitude during the second touchdown.</p><p>Sadly, while the simulations showed it was possible to avert the tragedy during the first bounce, it would have been very difficult for Yevdokimov to escape from the pilot-induced oscillation he was now experiencing. To quickly escape from such an event requires the mental clarity to understand the relationship between one’s own inputs and the response of the airplane, but someone who has that mental clarity is unlikely to get into a PIO in the first place. Most such events end only when the pilot gives up fighting, or in some rare and unfortunate cases, when the airplane breaks in some way. In this case, because the PIO took place so close to the ground, serious damage to the aircraft was almost inevitable.</p><p>As flight 1492 careened off the runway a second time, the combination of Yevdokimov’s ongoing full nose up input and the huge force of the bounce sent the pitch angle skyrocketing to 10 degrees nose up in the space of one second. The rate of upward pitch angle change was almost off the charts when Yevdokimov slammed his sidestick fully forward yet again. By then, the airplane was 15 feet in the air, almost back to the height where Yevdokimov initiated the flare in the first place. But almost immediately after pushing down, he felt the nose start to drop out from under him, so he pulled the sidestick back once again to full nose up. However, at that moment he must have realized that the bounce was too high to recover safely. In a spur-of-the-moment attempt to go around, he kept the stick fully aft and slammed the thrust levers as far forward as they would go, past the takeoff/go-around setting and into the MAX thrust position, a feature unique to the SSJ that provides 10% more thrust than TO/GA power in an emergency. Finally, it seemed he had broken out of the PIO, and if things had gone slightly differently, he might have saved the plane — but alas, it was not to be.</p><p>In one last tragic twist, because the reverser levers were already set to the reverse thrust position during the first bounce, the reverser doors automatically deployed during the second touchdown when the weight-on-wheels sensors detected that the plane was on the ground. The system is designed not to open the doors or produce reverse thrust if the plane is airborne, as a safety feature. Although the plane became airborne again before reverse thrust could actually be generated, the reverser doors were still open when Yevdokimov commanded max forward thrust. The safety system then prevented thrust from actually increasing before the reverser doors had closed, in order to prevent reverse thrust from being generated in the air. As a result, Yevdokimov’s last, desperate attempt to apply power elicited no response from the engines.</p><p>In the end, Yevdokimov could do nothing to stop the plane from crashing back to earth. A split second later, as the reverser doors swung closed, flight 1492 touched down a third time. This time the pitch was slightly nose up, with a vertical speed of 1,220 feet per minute (6.2 m/s), resulting in an impact force of at least 5.0 G’s, but probably higher. The landing gear instantly collapsed, a cloud of white fuel gushed out of the shattered fuel tanks, and the aircraft erupted in flames.</p><p>◊◊◊</p><p>The events of this Part, from the start of the flare to the ignition of the fire, took place in just 13 seconds.</p><iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FmgWSwbXMehI%3Ffeature%3Doembed&amp;display_name=YouTube&amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DmgWSwbXMehI&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FmgWSwbXMehI%2Fhqdefault.jpg&amp;type=text%2Fhtml&amp;schema=youtube" width="854" height="480" frameborder="0" scrolling="no"><a href="https://medium.com/media/1b01ad2b3cd928ac6410080f9c869b69/href">https://medium.com/media/1b01ad2b3cd928ac6410080f9c869b69/href</a></iframe><p>◊◊◊</p><h3><strong>Part 6: The Landing Gear Question</strong></h3><p>One of the most persistent public questions about flight 1492 was why the landing gear collapsed during the third touchdown, and why this collapse was able to breach the fuel tanks, triggering a catastrophic fire. This question is especially significant because European, American, and Russian certification regulations all require that the landing gear be designed so as to avoid this exact scenario. For instance, EASA regulation 25.721 states the following:</p><p><em>“The main landing gear system must be designed so that if it fails due to overloads during takeoff and landing (assuming the overloads to act in the upward and aft directions), the failure mode is not likely to cause…</em> <em>the spillage of enough fuel from any part of the fuel system to constitute a fire hazard.”</em></p><p>The Russian equivalent regulation, AR 25.271, contains identical wording.</p><p>Therefore, to understand why flight 1492 burst into flames on Sheremetyevo’s Runway 24 Left, we need to examine how the landing gear was designed and how it was tested.</p><p>Like most similar airplanes, the SSJ-100 main landing gear folds inward toward the fuselage, hinging about a cylindrical, longitudinally-oriented beam called the crossarm. The main landing gear leg descends from the crossarm. The leg is also braced by two diagonal, folding elements, of which the forward element is known as the drag brace and the aft element is known as the side brace.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*sssoU-y2s9l3WkICwkQnPg.png" /><figcaption>Diagram of the left main landing gear construction, viewed from ahead and to the left of the bogie. (MAK)</figcaption></figure><p>The forward end of the crossarm and the drag brace are both attached to the aft face of the wing box rear spar, a massive structural beam that runs from wing root to wing tip and forms the aft edge of the wing’s internal box structure. Meanwhile, the aft end of the crossarm and the side brace are attached to the landing gear crossbeam, which angles aft and inboard from the wing box rear spar to the fuselage.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dYnNqUSfvy6B4UdviTxkBQ.png" /><figcaption>The left main landing gear, viewed from behind with the wing structure. (MAK)</figcaption></figure><p>The significance of this information is that the rear spar also forms part of the wall of the fuel tank, which means that the tank could be breached if the crossarm and drag brace are ripped out of their attachment points. This is a vulnerability of essentially every transport aircraft, simply because this is the easiest and most efficient way to configure the fuel tank, the spar, and the landing gear. Therefore, every airliner is designed such that if the landing gear is subjected to a sufficiently large force, the aforementioned elements will separate in a sequence that prevents damage to the fuel tanks.</p><p>The SSJ’s landing gear, which was designed and produced by French company Safran, incorporates a set of “weak links,” or fuse pins, which are designed to fail under a slightly lower load than the rest of the landing gear. Four of these fuse pins attach the forward end of the crossarm to the rear spar, and four more attach the drag brace. Therefore, during a heavy impact the crossarm should cleanly separate from the rear spar without breaching the fuel tank, followed by the drag brace. The entire landing gear assembly should then rotate aft about the remaining attachment points, and the crossbeam should detach from the wing, causing the gear to separate in a rearward direction, away from the fuel tank. This is essentially the same design solution as every other similar aircraft.</p><p>When aerospace engineers design an aircraft component that will be subject to loading, they think in terms of two different load values: the design limit load, and the ultimate load. The design limit load is the size of the load that the component is expected to experience in service; or more specifically, the probability of a larger load is less than <em>n</em> per flight hour. Certification regulations typically require that the component be designed to withstand at least 1.5 times the design limit load before actually breaking, so engineers add a large safety factor. After accounting for this safety factor, the load at which the component will actually break is known as the ultimate load.</p><p>Certification regulations state that the design limit load may be incurred during a touchdown at maximum landing weight* with a vertical rate of at least 600 feet per minute (3.05 m/s), while the ultimate load may be incurred with a vertical rate at touchdown of 736 feet per minute (3.74 m/s). Because the impact force increases with the square of the velocity, this represents the required minimum safety margin of 1.5. The actual safety margin of most of the SSJ’s landing gear components, according to Safran, is above 2.0. The safety margin of the fuse pins, which were designed by UAC, was not provided to the investigation team, although it is by definition lower. However, based on the vertical velocity of flight 1492 during the second touchdown, and the effects thereof, I can say that it’s not more than 1.9.</p><blockquote>*Because the actual weight of flight 1492 at touchdown was very close to max landing weight, the accident scenario bears an acceptable resemblance to the certification scenario without adjusting the numbers to account for the weight of the aircraft.</blockquote><p>European, American, and Russian regulations provide some criteria against which manufacturers should test for the safe separation of the landing gear during a load application exceeding the ultimate load. For instance, EASA’s relevant regulation states the following:</p><p><em>“Failure of the landing gear under overload should be considered, assuming the overloads to act in any reasonable combination of vertical and drag loads, in combination with side loads acting both inboard and outboard up to 20% of the vertical load or 20% of the drag load, whichever is greater. It should be shown that at the time of separation the fuel tank itself is not ruptured at or near the landing gear attachments. The assessment of secondary impacts of the airframe with the ground following landing gear separation is not required. If the subsequent trajectory of a separated landing gear would likely puncture an adjacent fuel tank, design precautions should be taken to minimize the risk of fuel leakage.”</em></p><p>There are a couple things that have to be noted about this regulation. First of all, neither EASA nor any other regulatory body has established an exact definition of “reasonableness” when it comes to the combination of vertical and drag loads used by the manufacturer. Furthermore, the regulation doesn’t say how big the test load should be relative to the calculated ultimate load.</p><p>When UAC tested the landing gear separation sequence, they applied a rapidly and infinitely increasing load to the gear assembly until it separated. This test confirmed that the desired separation sequence would indeed occur, with the forward attachment point fuse pins failing first, followed by rearward rotation of the gear and finally separation of the aft attachment points. No damage to the fuel tanks was noted. The results of the test were accepted by EASA and the SSJ was certified as compliant.</p><p>But when the MAK examined the impact loads sustained by flight 1492, they found a key difference from the certification scenario. During the second touchdown, the vertical rate of the main landing gear at impact was -830 feet per minute, which exceeded Safran’s calculated ultimate load. But the landing gear didn’t separate — in fact, it didn’t appear to have been damaged at all, because no parts of the aircraft were found on the runway near the point of the second touchdown. So what actually happened?</p><p>As it turns out, the second impact fell into a gray area where the load was sufficient to break the fuse pins attaching the forward end of the landing gear crossarm to the wing box rear spar, but <em>not</em> the fuse pins for the drag brace or crossbeam. The ultimate load of the drag brace and crossbeam attachments is slightly higher than the crossarm forward attachment because the safest separation is achieved if the crossarm detaches from the spar first. But there was no requirement to test what would happen in the event of a marginal exceedance of the ultimate load that shears the crossarm fuse pins but not the rest. In fact, neither UAC nor Safran had any idea what would happen in this scenario because the tests involved a load that increased infinitely until the gear actually separated.</p><p>In theory, if the force of the second impact had been just a little bit higher, both main landing gears would have separated as designed, the aircraft would have crashed down onto its belly instead of bouncing, and the fuel tanks might not have been breached. In that case all occupants would have survived.</p><p>Instead, what happened was something far outside of the certification assumptions. Carrying the landing gear back into the air, intact except for the broken crossarm fuse pins, the aircraft bounced, then plunged back to earth with enormous force. Although the force of the third impact was measured as “at least 5.0 G’s,” against the second impact’s 5.85, in all likelihood the third impact was the more severe of the two. It would certainly have sheared the landing gear if the landing gear was intact, but it wasn’t. And because the expected failure sequence was no longer possible, the load path through the landing gear components was different than in the certification tests. Consequently, the landing gear actuating cylinder mounting brackets pulled out of the wing box rear spars, breaching both fuel tanks simultaneously and by an identical mechanism.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xjOKDSiyaI0icz66VGBPtw.png" /><figcaption>The damage to the wing rear spar caused by the landing gear failure, as it was found after the accident. (MAK)</figcaption></figure><p>Ultimately, the MAK was unable to assess the consequences of the third touchdown in terms of the certification requirements for two main reasons. The first is that the regulations explicitly do not require the manufacturer to consider the consequences of further impacts after an initial impact exceeding the ultimate load. And second, the vertical rate during the third impact was so large that the force exceeded the ultimate load of the wing structure itself. EASA certification requirements state that the airplane must not rupture in a manner catastrophic to safety during an impact without landing gear at a vertical rate up to 300 feet per minute. However, the actual vertical rate during the third touchdown was much greater than this, and extensive airframe damage was noted as a result, including the partial separation of the wing box forward spar from the fuselage. Therefore, no assurance against a catastrophic fuel tank breach existed even if the landing gear had separated normally.</p><p>But while the MAK concluded that the SSJ’s landing gear behaved in accordance with its certification basis during the crash, they reserved considerable criticism for the regulations themselves. The investigators pointed out that there was a lack of correlation between the regulations governing the maximum load the gear must withstand, and the regulations circumscribing the landing gear separation tests, which resulted in an intermediate area where the effects of a given load were not known. In this case, because the testing criteria were not required to resemble reality, the landing gear was subjected during testing to an infinitely increasing load, instead of a specific, finite load, as occurs in an actual accident. As a result, the testing criteria were insufficient to confirm that the design actually minimized the risk of catastrophic fuel spillage in a real world accident.</p><p>The MAK also argued that the lack of a requirement to examine the consequences of additional impacts should be reconsidered. The final report discusses five previous incidents in which multiple large loads in quick succession caused an unexpected landing gear failure sequence, out of which three cases resulted in fuel spillage sufficient to constitute a fire hazard, although none resulted in fatalities. These three cases included <a href="https://admiralcloudberg.medium.com/powerless-over-london-the-crash-of-british-airways-flight-38-7b2e20075f26">British Airways flight 38</a>, a B777 which landed short of the runway in London in 2008, and Yakutia Airlines flight 414, another SSJ that overran a runway in 2018. In both cases, investigators recommended enhancing the certificating test requirements to include multiple touchdown scenarios, but these recommendations were rejected by the European and Russian regulators respectively.</p><p>In theory, an analysis of the landing gear behavior during a second impact exceeding the ultimate load following a first such impact could be possible. Because the landing gear is designed to separate in a controlled way with a predictable failure sequence, the condition of the gear at the time of a second impact could be calculated. And while I am not in a position to say with certainty whether such testing would result in practical design improvements that might prevent a tragedy like Aeroflot flight 1492, the MAK and I share a belief that regulators should explore the possibility.</p><p>Unfortunately, for those who found themselves aboard flight 1492, all of this discussion comes too late.</p><p>◊◊◊</p><h3><strong>Part 7: Hell</strong></h3><p>As flight 1492 crashed back to earth for the final time, the fuel tanks split open, and a torrential blast of jet fuel poured directly onto the hot engine exhaust nozzles, causing a deflagration of the entire fuel-air mixture. Bright flames billowed out of the fuel cloud, streaming behind the aircraft as it slid down the runway.</p><p>On board the aircraft, Captain Yevdokimov moved the thrust levers back to max reverse, but no reverse thrust was generated because the weight-on-wheels switches had been destroyed. First Officer Kuznetsov called out that they had no reverse thrust or spoilers. The wheel brakes were also out of commission, but the plane was still slowing down due to friction alone.</p><p>Decelerating through 100 knots, the intense smoke and fire behind the aircraft triggered a rear baggage compartment smoke alarm. From the cabin, passengers could see flames pouring from both wings, and video footage recorded from inside the plane captured the sound of panicked screaming.</p><iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2Fedy3e24yVIc%3Ffeature%3Doembed&amp;display_name=YouTube&amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3Dedy3e24yVIc&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2Fedy3e24yVIc%2Fhqdefault.jpg&amp;type=text%2Fhtml&amp;schema=youtube" width="854" height="480" frameborder="0" scrolling="no"><a href="https://medium.com/media/4642ace3e2b4fbc9d1084312a96c0bdf/href">https://medium.com/media/4642ace3e2b4fbc9d1084312a96c0bdf/href</a></iframe><p>At 80 knots, decreasing rudder authority began to interfere with Yevdokimov’s ability to keep the nose pointed straight ahead, and the plane started to fishtail like a car with no rear tires. Flight 1492 veered hard to the left, as though the tail was trying to overtake the nose, until the plane was sliding sideways down the runway, leaving a trail of towering flames and smoke in its fuel-soaked wake. It was only at this point that the flight crew caught sight of the flames and realized they were on fire. At almost the same time, the senior flight attendant called the cockpit via the interphone and exclaimed, “Fire on board! Fire!”</p><p>As the aircraft slid off the left side of the runway and screeched to a halt, the fire expanded rapidly, enveloping everything aft of the wings in an angry, billowing tempest of pure flame. Every surface behind the fuel tanks had been sprayed with aerosolized fuel, which was then blown directly against the right side of the fuselage as the plane slid sideways across the runway. Even worse, as the plane became stationary, all the fuel escaping from the tanks pooled underneath the fuselage, intensifying the inferno, which was then further stoked by the hot exhaust blasts shooting from the still-running engines.</p><p>By the time the plane stopped, the fire had been burning for 30 seconds. In the cabin, the passengers did not need 30 seconds to determine that they were in mortal danger, and many began to get up from their seats while the plane was still moving. Others screamed, some attempted to call loved ones, and many simply sat there in shock.</p><p>Up front, the two forward flight attendants realized during the landing roll that the plane was on fire. There had been no request from the crew to be ready for an evacuation, nor had there been a call to brace for impact, but it was immediately obvious to the cabin crew that the evacuation would need to take place without delay. Exercising her prerogative, Senior Flight Attendant Kseniya Fogel’ stood up from her seat as soon as the aircraft stopped and opened the R1 door without waiting for a command by the pilots. By 18:30:46, just eight seconds after the plane came to a stop, the door opened and the slide began deploying.</p><iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FgmcFsz9fuoY%3Fstart%3D58%26feature%3Doembed%26start%3D58&amp;display_name=YouTube&amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DgmcFsz9fuoY&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FgmcFsz9fuoY%2Fhqdefault.jpg&amp;type=text%2Fhtml&amp;schema=youtube" width="854" height="480" frameborder="0" scrolling="no"><a href="https://medium.com/media/80a6646b6e9050967773ad8ef771b94a/href">https://medium.com/media/80a6646b6e9050967773ad8ef771b94a/href</a></iframe><p>Meanwhile in the cockpit, at the moment the plane stopped, First Officer Kuznetsov called “Attention crew! On station. Attention crew! On station,” the standard call for the cabin crew to prepare for an evacuation, but he forgot to depress the interphone button and broadcast this using VHF radio 2 instead. Air traffic control did not hear the call because the VHF 2 antenna had already been destroyed by the fire. Instead, Kuznetsov turned and shouted “Evacuation,” and one of the flight attendants yelled, “We are on fire!”</p><p>As the R1 slide was deploying, one of the flight attendants attempted to make a public address system announcement, “Seat belts off, leave everything, get out!” But she forgot to press the PA button and this command was broadcast to the cockpit via the interphone instead. Only a few passengers at the front heard the command to “leave everything.” Farther back, this command would have been useful, because some passengers in the traffic jam in the aisle were opening the overhead bins to retrieve various items, making the jam even worse.</p><p>Up front, Captain Yevdokimov called for the emergency evacuation checklist, and Kuznetsov scrambled around trying to find the QRH, which had fallen under his seat during the crash. After laying his hands on it, he tried again to call for the evacuation, but his voice was not heard in the cabin for unknown reasons. Regardless, by then the evacuation had already started, as passengers began to jump down the R1 slide, about 7 or 8 seconds after the door was opened. One of the flight attendants then crossed the galley and opened the L1 door too. A split second after that, the cockpit voice recorder ceased recording as the fire destroyed the cables connecting it to the microphones.</p><p>By the time the first passengers hit the bottom of the slide at 18:30 and 54 seconds, the situation in the back of the plane was already apocalyptic. Video evidence showed that within one second of the first passenger leaving the plane, and possibly even earlier, the fire breached the fuselage and began spreading into the cabin itself — with all of the passengers still inside. The intense heat of the blaze caused the cabin windows to shrink and fall out of their frames, creating multiple entry points all along the last few rows no later than 49 seconds after the start of the fire. Before the evacuation even began, the entire back of the plane filled up with dense smoke as far forward as row 9,* which according to survivors was so toxic that two to three breaths were enough to incapacitate a person.</p><blockquote>*With the business class configuration on flight 1492, there were no rows 4–5, so row 9 was actually the 7th row, out of 18 total (ending in row 20).</blockquote><p>The rearmost person on flight 1492 was 21-year-old flight attendant Maksim Moiseev. None of the survivors reported seeing him, and what he did in the few seconds available to him will never be fully known. Surrounded by choking smoke and unable to see, he somehow managed to open the 2L door, but because this door was inside the seat of the fire, the resulting blast of heat most likely killed him instantly. His body was later discovered on the ground just outside the open door, the only victim found outside the plane. Although opening this door could in theory have enhanced the spread of the fire into the cabin, the windows had already failed by this point and simulations showed that opening the door made no difference.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/720/0*Ebuh452NeQVlffDj.jpg" /><figcaption>Fire trucks respond to the burning aircraft, as seen from another flight parked at the gate. (France 24)</figcaption></figure><p>Twenty-one passengers were seated in rows 16 to 20 at the back of the plane, of whom only the passenger in seat 18A lived to speak of what took place there. By his recollection, a serious jam formed in the aisle, akin to a crowd crush, as panicked passengers tried to push forward before the aircraft had stopped moving, and therefore before those ahead had a chance to get out of the way. Black smoke quickly enveloped the crowd and he could hear people calling out to him, but there was nothing he could do for them. Crawling on all fours to stay below the worst of the smoke, he encountered the jam in the aisle, but managed to get around it by holding his breath and climbing over the seat backs. By the time he reached the nose section it was clear of people — so what was causing the blockage?</p><p>The only survivor out of nine people seated in rows 14 and 15 was the passenger in seat 15C. She reported that after seeing fire during the landing roll, she undid her seat belt and got up while the plane was still moving, but when she tried to move forward, a traffic jam developed because people were trying to retrieve luggage from the overhead bins. Everything behind her row was consumed by thick smoke and it quickly became difficult to breathe. Struggling forward, she saw a man who had stopped to grab his luggage and was blocking people from moving, although she didn’t say whether he was ahead of or behind her, or how she got around him.</p><p>The passenger in business class seat 3A said that he stayed in his seat for 30 seconds to let people who were advancing from the back escape first, until the smoke enveloped him too. He joined the line of people moving forward and managed to escape, but before he left the aircraft he saw people getting their bags from the overhead bins, including some very large bags that in his opinion definitely impeded the evacuation.</p><p>In the cockpit, the pilots tried to complete the evacuation checklist, which included steps like setting the parking brake and shutting down the engines. Physical evidence confirms that they made it to at least step 6, and step 9 might have been accomplished as well, but the checklist was never completed. The engines weren’t shut down until 18:31 and 34 seconds, almost a minute after the plane came to a stop. Given that the pilots could have shut down the engines in mere seconds using the master switches, the MAK wrote that this was an unreasonably long time to leave them running. Furthermore, the jet blasts significantly contributed to the size and speed of the fire, reducing the amount of time for the passengers to escape. Publicly available videos of the evacuation clearly show that the fire became less energetic as soon as the engines were shut off, testifying to their influence.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*c0X-IT1NUgJRF55n6RBzLA.png" /><figcaption>The difference in the size of the fire plume before and after the engines were shut down. These screenshots were taken just 10 seconds apart. (Igor Trunov)</figcaption></figure><p>At around the time the engines were shut down, flight attendants Fogel’ and Kasatkina were still standing by the exits, shoving passengers down the slides. But after evacuating a little over two dozen people, no more passengers emerged from the smoke-filled cabin. Since the fire and smoke were still getting worse with every passing second, both flight attendants elected to abandon ship.</p><p>But back in the pall of darkness, several passengers were still trying desperately to leave. A total of four passengers eventually left the aircraft after the flight attendants, escaping from the very margin of the inferno. The first of these was the passenger from seat 15C, who jumped through the door to safety after suffering burns to 15% of her body. Also still on the airplane was the passenger from seat 12A, who encountered First Officer Kuznetsov just outside the cockpit and decided to stay to help more passengers. Together, this passenger and Kuznetsov dragged a nearly unconscious woman out of the aisle and pushed her down the slide, followed by the man from seat 18A, who beat the odds by making it just far enough forward for the angels at the doorway to spot his arms sticking out of the smoke. After being flung bodily down the slide, he came to his senses, got up, and walked away.</p><p>At this point the passenger from seat 12A told Kuznetsov that they should find portable breathing equipment and try to enter the cabin to search for more people. Kuznetsov tried to shine a flashlight into the haze to get a better sense of the conditions, but the beam was unable to penetrate the dense fumes. Concluding that there was nothing more they could do, Kuznetsov declared, “It’s over, let’s go,” and passenger 12A reluctantly fled the burning plane. He was the last surviving passenger to leave, 106 seconds after the start of the evacuation. Out of all the survivors, only he and passenger 18A saw the flames inside the cabin and lived to speak of them. All others close enough to see that eerie sight did not survive.</p><p>After passenger 12A departed the plane, First Officer Kuznetsov returned to the cockpit, then exited via the window 35 seconds later. But after less than a minute on the ground, he bizarrely climbed back in through the escape slide and threw his flight bag and raincoat out of the plane, before following them down the slide. The MAK wrote that they were unable to “reliably identify the purpose” of these actions by Kuznetsov, and in fact the report contains no testimony from him at all, suggesting that Aeroflot did not make him available for an interview.</p><p>Captain Yevdokimov was the last person to leave the plane alive, at time 18:36 and 12 seconds, over five minutes after the start of the evacuation and after the fire had already been partially extinguished by responding fire crews.</p><p>By the time fire crews entered the aircraft with smoke protection equipment and hand lines, there was no chance of survival for anyone still inside. The MAK did note that prepositioning the fire trucks could have cut the first vehicle’s response time by 40 to 45 seconds, resulting in its arrival only 20 seconds after the plane stopped. However, this probably wouldn’t have saved any lives because the fire had already penetrated the cabin interior by that point. Investigators speculated that if one or more crewmembers had donned protective breathing equipment and entered the forward cabin, a couple more people might have been saved, but this would have been far outside any pilot or flight attendant’s job description.</p><p>◊◊◊</p><p>In total, 41 out of the 78 passengers and crew did not escape the burning jet. But there is more to be said about how they died, and how their deaths might or might not have been prevented.</p><p>In most aircraft accidents involving large numbers of fire deaths, the killer of most or all of the victims is smoke inhalation. Smoke generated by burning plastics and hydrocarbons contains deadly chemicals such as carbon monoxide and hydrogen cyanide that can quickly reach fatal concentrations in a smoke-filled cabin. As perhaps the most well-known example, in the 1<a href="https://admiralcloudberg.medium.com/fire-on-the-runway-the-manchester-airport-disaster-and-the-tragedy-of-british-airtours-flight-28m-0a2054e27fff">985 Manchester runway disaster</a>, out of 55 people who died trying to escape the burning 737, only 6 died directly due to the fire; the rest were killed by the smoke.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*sFUH2ICakYI7KNLRMkd3oQ.png" /><figcaption>The seating map of survivors vs. fatalities is one of the starkest I’ve seen. (MAK)</figcaption></figure><p>But in the case of Aeroflot 1492, the usual logic didn’t hold. Autopsies determined that while most passengers had breathed in at least some toxic smoke before dying, the cause of death in 40 out of 41 cases was direct thermal assault. Calculations showed that once the windows failed, the temperature at head height in the aft part of the cabin would have very quickly exceeded 600˚C, causing the passengers in this area to burn to death before they had a chance to succumb to the fumes. At least two passengers in row 17 were found still belted into their assigned seats, indicating that they were overcome almost instantly. One of these, the passenger in seat 17E, was found to have died by cardiac arrest, perhaps due to shock; he was the only victim whose cause of death was not listed as “burning.”</p><p>Most of the victims were found very close to their seats in the aft cabin, indicating that they didn’t have a chance to get very far. Out of 46 people seated in rows 11 to 20, only six survived, all whom started moving toward the exit before the plane had come to a stop; those who waited or became stuck ran out of time. That being said, if you ever find yourself in a situation requiring an emergency evacuation, you should not attempt to get up before the airplane comes to a stop, because 99 times out of 100 this will just make the evacuation more chaotic. Flight 1492 was a special case with few parallels in history.</p><p>Given the speed with which the fire overran the cabin, it was impossible to save everyone. However, an unknown number of passengers — the report simply states “several” — were found piled up between rows 6 and 10. At the same time, all but one of the passengers originally seated in this area survived, indicating that these victims had made their way from further back. A pile in this location is consistent with witness reports of a traffic jam behind one or more passengers who were retrieving baggage from the overhead bins. The passenger in seat 15C confirmed seeing a man grabbing baggage shortly before she left, as well as several people attempting to move forward behind her, of whom only two escaped. Furthermore, these victims had already left the fire zone by the time they collapsed; in fact, the autopsies showed that they were incapacitated by toxic fumes while trying to leave, and were killed by the fire while unconscious on the floor. Given this information, it’s entirely possible that some of these passengers, likely a number in the low single digits, may have survived if other passengers had not tried to retrieve their luggage from the overhead bins. In the end the MAK determined that this behavior by passengers did contribute to the high death toll.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*K07hKLCEJOU2stSGkgIVIw.png" /><figcaption>Remarkably, passenger baggage in the aft cargo compartment largely survived the blaze. (MAK)</figcaption></figure><p>In the aftermath of the accident, many people were quick to blame these passengers. In one sense, this blame is constructive insofar as shame is an effective motivator for people who might otherwise try to get their luggage during a future evacuation. However, research has shown that when untrained civilians are unexpectedly placed into an emergency aboard an aircraft, many people’s brains revert to what they already know, which is to stand up, grab their bags, and walk to the exit, as though nothing is wrong. This behavioral tendency can be short-circuited if the flight attendants loudly and assertively order passengers to leave their bags behind and exit immediately. But on flight 1492, the order to leave bags behind was not heard by the majority of the passengers because the senior flight attendant forgot to press the PA button before making the announcement.</p><p>In the MAK’s opinion, this omission could have occurred because the cabin crew were type rated on multiple aircraft at once, but each recurrent performance check took place on one aircraft type only. As a result, two out of the three flight attendants on flight 1492 hadn’t been checked out on an SSJ in over a year, which can result in a degradation of emergency skills.</p><p>If, god forbid, you ever find yourself in a similar situation, my hope is that this story will come to mind. There is nothing in your carry-on bag that’s worth more than human lives. If you have important items with you, like ID or medications, keep them in a small bag or personal item that can stay with you at your seat; this will reduce the temptation to retrieve your carry-on. Backing up the contents of electronic devices like laptops before flying can also help ease the decision to leave them behind. But most of all, my advice is to remember the victims of flight 1492, and learn from their fate.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*gb4Y5ibzAC5ThR1A0aG_wg.png" /><figcaption>The difference in damage between the fore and aft parts of the fuselage was extreme. (MAK)</figcaption></figure><p>◊◊◊</p><p>In the end, the MAK concluded that the primary causes of the fire’s severity were the large amount of fuel involved and the blowtorching effect of the engines, which created a fire scenario that would have quickly overwhelmed even the most robust protections. Contributing to the number of deaths were the lack of usable exits at the rear; a crowd crush caused by panic in the tail section; and passengers stopping in the aisle to retrieve baggage.</p><p>The MAK report does not trade in matters of blame or praise, but I do want to independently praise the actions of the flight attendants, First Officer Kuznetsov, and passenger 12A (identified as Sergei Kuznetsov, no relation to the first officer), who helped save lives by pushing people out the exits and then dragging additional people to safety. But out of all the crewmembers, my sympathy is extended most of all to Maksim Moiseev, who had no time to act and no chance of survival. If he had been given just one minute more to live, he no doubt would have done all he could to save his passengers, but the universe does not always grant us that privilege.</p><p>◊◊◊</p><h3><strong>Part 8: The Truth Is Always More Complicated</strong></h3><p>Almost every fatal air disaster begets a blame game — a circle of pointing fingers, a flurry of lawsuits, an interpretation and reinterpretation of investigative findings. But few accidents have devolved so deeply into this cycle of mutual accusation as has Aeroflot flight 1492. From the very first days, speculation abounded. Some suggested that the crash was caused by a flaw with the much-maligned SSJ-100; others pointed out what they felt were obvious flight crew errors; many brought up Aeroflot’s sordid safety record and reputation for negligent behavior; and quite a few focused their ire on the passengers who stopped to grab their carry-on bags.</p><p>The MAK’s job was to find the factors that caused or contributed to the accident, while staying above the mudslinging — not an easy task, as it turns out. Their job was complicated at every step by various actors. Less than 24 hours after the crash, Captain Yevdokimov was giving public interviews to the media, even though proper protocol is to isolate crewmembers until investigators have had a chance to speak to them. In the end, the MAK was not able to interview Yevdokimov until after he had been briefed on the contents of the black boxes, which contaminated his account of events and made it difficult to tell what was his actual impression at the time, and what was an invention to explain the data.</p><p>It certainly didn’t help that under Russian law, a parallel criminal inquiry is automatically opened into any air accident even if no firm evidence of a crime has been uncovered. The fact that he could be charged by this inquiry almost certainly colored Yevdokimov’s statements to the MAK and impeded the investigators’ ability to determine what he was actually thinking during the flight. Unfortunately, Yevdokimov’s fears proved well-founded, and the Investigative Committee of Russia charged him with “violating flight safety rules” on October 2nd, 2019. Although the Investigative Committee possessed wide latitude to charge anyone found to have acted inappropriately, Yevdokimov was the only person accused.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/900/0*8na1oGZiz8TuGP1A" /><figcaption>The remains of the aircraft are lifted away by a crane during the cleanup. (Eurasian Times)</figcaption></figure><p>The practice of criminally prosecuting pilots who make mistakes that contribute to fatal accidents has been widely criticized by both legal and aviation experts around the world, because it complicates the work of safety investigators — as seen in this case — and because it often results in scapegoating of an individual who may have been failed by an airline’s training program. The practice also raises ethical concerns when the threat of prison becomes involved, given that the accused individual almost never presents a danger to others. Unfortunately, Russia has a long history of ignoring these concerns and prosecuting the people who were directly involved in an accident while ignoring the people and institutions who systemically degraded the safety environment.</p><p>In 2023, the court found Yevdokimov guilty on all charges. In addition to suspension of his license, he was fined 2.5 million rubles (about US$30,000) and sentenced to 6 years in a prison colony. It is unclear to me who was supposed to be satisfied by this ruling. With his license suspended, there was no way for him to cause additional accidents, and none of the survivors or next of kin publicly lodged any accusations against him.</p><p>Forced to defend himself in court, Yevdokimov argued that the aircraft did not respond normally to his inputs and was almost impossible to control, suggesting that the manufacturer had designed the fly-by-wire system improperly and without adequate protection against lightning. His lawyers also argued that the landing gear was not adequately designed to prevent fuel spillage in a crash landing, and — quite distastefully — blamed the large number of victims on the late flight attendant Maksim Moiseev for opening the rear door, despite the MAK’s finding that this had little effect on the spread of the fire.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/645/0*g3mL7WmdTxLDnSSy.jpg" /><figcaption>Denis Yevdokimov in the courtroom during his trial. (TASS)</figcaption></figure><p>On the other hand, when the MAK published its final report on March 28, 2025, Russian media mostly wrote that the report blamed the pilot, without much discussion of the contents. Over the course of this article, I’ve already explained most of what the MAK found, but I now want to go over the actual takeaways that should be gleaned from those findings, as well as the areas where safety improvements are needed. This following section will be broken into three subParts: (1) <em>The Aircraft, </em>(2)<em> The Pilot,</em> and (3) <em>The Airline.</em></p><p><strong><em>Part 8.1: The Aircraft</em></strong></p><p>During its investigation, the MAK did not find evidence that the SSJ-100 fell short of its own certification basis. The forces imparted to the landing gear were outside those envisioned by regulatory requirements, and testing showed that the aircraft’s reactions to the pilot’s control inputs corresponded very closely to the manufacturer’s model. Furthermore, flight testing by EASA and MAK experts in Italy allowed investigators and safety officials to determine through first-hand experience that the aircraft’s behavior in Direct Mode is controllable using conventional piloting skills and does not necessarily constitute a danger in and of itself. As for the failure of both EIUs during the lightning strike, the MAK was not able to establish a cause.</p><p>However, the narrow conclusion that the SSJ met certification requirements does not exonerate the design. As I discussed in Part 6, the MAK criticized the regulations themselves for providing inadequate assurance against a catastrophic rupture of the fuel tanks during a real-world crash landing. But in addition to that, the MAK pointed out a few areas where the design of the aircraft could have been better, despite technically meeting requirements, and I want to add a few points of my own to that list as well. In fact, after all my research into flight 1492, I came to believe that design decisions by UAC significantly contributed to the accident.</p><p>Although the MAK didn’t discuss it at all, in my opinion one of the most significant issues with the SSJ’s fly-by-wire philosophy was its lack of an equivalent to Alternate Law, as I discussed in Part 3. According to official SSJ training documents, a reversion to Direct Mode can occur “if parameters from ADS [the air data system] or IRS [the inertial reference system] are not available,” a condition that would cause an Airbus to enter Alternate Law. To reiterate, this makes a Direct Mode reversion much more likely on the SSJ than on any other fly-by-wire aircraft. Now, to be clear, my research suggests that if the flight control computers temporarily stopped receiving any data from the entire air data and inertial reference system, as happened in this case, even an Airbus would have entered Direct Law. However, this comparison is misleading because the Airbus doesn’t appear to have a 1:1 equivalent of the Electronic Interface Units.</p><p>In order to better understand what the EIUs do and why they exist, I dived into hundreds of pages of SSJ-100 documentation, and in the process I got more than I bargained for. As I stated earlier in this article, the purpose of the EIUs is to reformat data into the configuration demanded by the recipient computers. What actually happens is something called <em>protocol adaptation</em>, which is pretty far outside my wheelhouse, but you can think of it as a translation between two ways of organizing information, which could be feet vs. meters or morse code vs. signal flags or apples vs. oranges, it doesn’t matter. In any case, according to the SSJ documentation, the EIUs “perform a similar function to the data concentration system,” and one of the functions of the data concentration system is to “perform protocol adaptation to enable off the shelf equipment to communicate together.” Further, the documentation shows that the EIUs provide protocol adaptation of analog, discrete, and digital inputs for practically every aircraft system, from the primary flight control computers to the full-authority digital engine control to the brakes to the auxiliary power unit to the air conditioning to the cockpit window heaters. In the case of the flight controls, the documentation shows that the EIUs translate data encoded using an unspecified original digital protocol (possibly ARINC-664) to and from another digital protocol called ARINC-429, which I don’t understand and you don’t need to either.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*byTmg9Q7Xs76kRqhZKazsQ.png" /><figcaption>A table of systems for which the EIU performs protocol adaptation. (Superjet International Training Center)</figcaption></figure><p>As far as I have been able to tell, on Airbus aircraft this function is not necessary, or where it is, it’s performed at each individual connection between a data source and the data recipient (such as an air data computer and a flight control computer). There certainly isn’t a centralized unit that does protocol adaptation for every single aircraft system. So why does the SSJ have one?</p><p>The most likely answer, as the above quotations imply, is that sensors, computers, flight controls, instruments, and so on come from a variety of suppliers, and most of these components are off the shelf, rather than being custom-made for the SSJ. In the case of the fly-by-wire system, the air data and inertial reference computers appear to have been designed by Thales in France, while the PFCUs were designed by Liebherr in Germany. Now, this isn’t always a problem, but for UAC it was, because the company was unlikely to sell enough SSJs to make it economical for suppliers to customize their components for the SSJ. And without that customization, off the shelf avionics aren’t necessarily capable of talking to one another. For instance, on Airbus aircraft (and correct me if I’m wrong), the air data computers are made by Thales but the flight control computers are made by Safran, so when a new Airbus is being designed those two companies sit down and work out how they’re going to make their devices talk to each other. At the same time, Liebherr produces flight control systems for the Embraer E-series, which are designed to connect to computers made for the E-series by BAE Systems. As far as I can tell, most Airbus aircraft use ARINC-429, while some Embraer jets use ARINC-664. So my guess is that when UAC ordered Thales air data computers but Liebherr flight control computers, they didn’t have a common digital protocol, and something was needed to translate between them. And in fact, this was probably the case for a wide variety of systems that had mix-matched components. Therefore, UAC resolved the resulting tangle of different protocols by routing everything through the EIUs, because they couldn’t get the individual suppliers to customize their products for the SSJ. The only things that were custom made were the EIUs themselves, which explains why they were among the only avionics on the entire aircraft to be designed and built in Russia.</p><p>However, the decision to route everything through the EIUs de-compartmentalized a large number of aircraft systems by shoving everything through this one pair of computers. Furthermore, it negated the redundancy provided by having three ADCs (air data computers), three IRSes, and three PFCUs (primary flight control units) by processing the ADC and IRS signals through only two EIUs. Unlike the Airbus, alternate routes for certain parameters were not available.</p><p>Wrapping back around to where I started this argument, a failure of all protocol adaptation for the flight control system isn’t something that’s realistic on the Airbus but could happen on the SSJ. The two EIUs, being identical, were equally vulnerable to environmental effects such as lightning. This goes for any group of redundant computers that are structurally identical, but in this case there was some common flaw that allowed lightning to affect the power supply to both units by the same mechanism, which was not anticipated by the manufacturer. What’s significant is that this flaw, whatever it was, involved the one computer that was tied to almost everything, the lynchpin of the SSJ’s network of automated functions. It’s worth pointing out here that this type of event is avoidable, as evidenced by my failure to find any record of an Airbus suffering a flight control law reversion due to a lightning strike, despite the Airbus fleet having accrued several orders of magnitude more flight time. This fact certainly raises questions about whether the EIU manufacturer, Ulyanovsk Instrument Bureau, is capable of designing avionics that meet modern expectations of reliability. Remember what I said about Russia’s high-tech aerospace industry being 20 years behind?</p><p>This particular issue is likely just one of many that are collectively responsible for the SSJ’s high rate of flight control law reversions. Some of those reversions may have been less severe if the SSJ had an Alternate Law, but at first glance it seems that flight 1492 still would have entered Direct Mode even if Alternate Law had existed, because all air data was interrupted when the EIUs rebooted. But on the Airbus, it’s sometimes possible to upgrade from Direct Law to Alternate Law if the original failure goes away, depending on the nature of the failure. That’s because there are many fly-by-wire functions that can be restored in flight without pilot action, and Alternate Law’s several sub-states allow for selective loss or restoration of functions. Because the original failure on flight 1492 entirely went away after less than 18 seconds, a hypothetical SSJ with Airbus flight control laws could have jumped from Direct Law back to Alternate Law as soon as the PFCUs started receiving valid data from the ADCs again, which would have restored normal sidestick operation and autotrim. Any systems requiring complex pilot action to restore could have remained off with their associated functions inoperative. But without these capabilities, flight 1492 became stuck in Direct Mode even though all aircraft systems except VHF radio 1 were completely serviceable.</p><p>Because of this problem, the MAK recommended that UAC explore the feasibility of enabling a return from Direct Mode to Normal Mode in flight.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*SNRRG9ETsKJHZ5wi.jpg" /><figcaption>The burned interior of flight 1492’s cabin. (ABC News)</figcaption></figure><p>◊◊◊</p><p>Another issue I want to highlight is that pilots have to keep their conventional flying skills sharp in order to handle Direct Mode/Law reversions, no matter whether they’re flying an SSJ or an Airbus. But because the SSJ is so much more likely to enter Direct Mode than an Airbus is <em>by design,</em> even before accounting for the unexpectedly high failure rate, the relative importance of this issue is much higher on the SSJ. Even with consistent training, a pilot’s instinctive use of the trim atrophies when flying a fly-by-wire aircraft, not to mention that flying with no control modulation for airspeed <em>and</em> no force feedback is just plain hard.</p><p>Here I want to highlight a different type of fly-by-wire philosophy that is used on the Boeing 777 and the Airbus A220 (which began life as a Bombardier product). On those aircraft, the autotrim adjusts the stabilizer to maintain an invisible “trim reference speed.” The trim reference speed is set by the pilot using trim switches on the yoke, which in a conventional aircraft would move the trim itself. Using the flight controls to deviate from the trim reference speed generates artificial force feedback on the yoke. So if the trim reference speed is set to 200 knots, and the pilot wants to slow to 180 knots, the pilot can pull back to raise the nose, which will cause the speed to drop, but the pilot will feel resistance. This resistance is removed by adjusting the trim reference speed using the trim switches until the reference speed matches the desired speed. The autotrim will then maintain the new reference speed until the pilot changes it — nose up to slow down, nose down to speed up. For the pilot, this entire sequence feels very similar to trimming a conventional aircraft where the trim switches directly move the stabilizer, but instead of reacting to speed changes by trimming, the pilot proactively trims in order to initiate speed changes, while the autotrim keeps the speed stable when the pilot isn’t making inputs.</p><p>One of the advantages of this design is that if the system reverts to Direct Mode, the trim switches on the yoke (or on the A220, the sidestick) become directly connected to the trim. Then, if the pilot encounters resistance when maintaining the desired speed or flight path, they can simply use the same trim switches in exactly the same way as they would in Normal Mode to re-trim the aircraft. This makes flight in Direct Mode on the 777 and A220 much easier than in the A320 or the SSJ. The downside of this design relative to the A320/SSJ system is that it’s possible to be out of trim in Normal Mode, which can significantly increase pilot confusion during an in-flight upset, as well as increasing the standard workload.</p><p>On the SSJ, with no Alternate Law and a comparatively high likelihood of reverting to Direct Mode, a Boeing-style trim system would have significantly reduced the inherent risk associated with a reversion. Airbus aircraft (excluding the A220) can get away with a control law philosophy that requires very different flying techniques in Direct Law because these aircraft almost never enter Direct Law to begin with,* thanks to the existence of Alternate Law. The SSJ doesn’t have that luxury. As a result, it’s safe to say that the SSJ’s fly-by-wire philosophy is inferior to both the Airbus and Boeing variants from a safety standpoint.</p><p><em>*Except during Alternate Law reversions after extending the landing gear on the A320. However, this should take place after all major maneuvers are complete.</em></p><p>◊◊◊</p><p><strong><em>Part 8.2: The Pilot</em></strong></p><p>The data from Denis Yevdokimov’s last 37 flights before the accident demonstrate that he never developed a correct flare and landing technique. He had a dangerous tendency to pitch up too far during the flare then correct by pitching down, which may have been exacerbated by the SSJ’s lack of a Flare Law, but ultimately comes down to individual technique. But proper technique is something that should be drilled into a pilot by the training program, so I’m going to discuss that aspect in Part 8.3. What I want to highlight here instead is the issue of judgment.</p><p>Although there were a few points during the flight where Captain Yevdokimov displayed good judgment, such as following the SID when he lost radio contact, most of the flight was marked by a series of poor judgment calls.</p><p>Before the flight, he demonstrated a cavalier attitude toward thunderstorms in the area, even though every pilot knows these storms can contain severe or even catastrophic hazards. Most other pilots departing Sheremetyevo that day requested a deviation from the SID to avoid the storms, but Yevdokimov didn’t even try, and that bothers me. Pilots need to actively estimate the threat posed by factors outside their control, such as weather, and they need to modify their plans to account for them. Flying into the thunderstorm without even trying to steer clear was simply careless.</p><p>After the lightning strike, Yevdokimov did not attempt to systematically diagnose the cause of the problems with the plane or establish what actions were required to return safely to the airport. Much as he did when confronted with bad weather, he displayed a general incuriosity toward flight safety hazards. That’s not to say he was unaware that his difficulty controlling the plane represented a hazard, but rather that he reacted by attempting to exit the situation as quickly as possible without attempting to understand it. This occurred despite the fact that the consequences of a Direct Mode reversion were clearly spelled out in the QRH. But First Officer Kuznetsov displayed similar incuriosity when he sped through the QRH section on Direct Mode in a robotic and disinterested manner, as though he was just going through the motions of reading. It’s disturbing that the pilots engaged in no discussion of the contents of this section despite having unanswered questions about what the plane was doing.</p><p>This lack of understanding caused Yevdokimov to believe that the situation was more serious than it actually was, which in turn caused him to start rushing without sufficient forethought. He initiated the approach without checking with Kuznetsov and without circling to assess the condition of the airplane, even though he wanted to do so, as evidenced by his abortive request for a holding pattern. Then once the approach began, he again displayed poor judgment when he decided to continue to touchdown despite windshear and glideslope warnings.</p><p>All of the above decisions reflect poorly on Yevdokimov’s attitude. To explain these personal deficiencies, the MAK report cites certain psychological factors identified in his psychological exam, but this section was redacted from the report due to Russian privacy laws.</p><p>The series of hard landings were primarily caused by poor piloting skill, with the captain’s poor understanding of Direct Mode as a contributing factor. However, I view these issues as primarily training-related and will discuss them in part 8.3. Before concluding this section, I want to mention that Yevdokimov correctly decided to go around after the second bounce, but was thwarted because he had already deployed the thrust reversers. Going around after deploying the reversers is a violation of standard operating procedures for precisely this reason. Considering the above, Yevdokimov was in a situation where the bounced landing procedures required him to go around, but the reverser deployment rule required the opposite. The answer to this contradiction is to avoid selecting reverse thrust until after the spoilers have deployed, which should prevent the plane from bouncing. In Normal Mode, this happens automatically, but in Direct Mode the pilot has to remember to deploy the spoilers, which Yevdokimov didn’t. As a result, the MAK recommended that UAC enable automatic spoiler deployment in Direct Mode.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/789/0*9eyUnzgiL8uZjy-S" /><figcaption>Rear view of the aircraft remains. (MAK)</figcaption></figure><p>◊◊◊</p><p><strong><em>Part 8.3: The Airline</em></strong></p><p>In its final report, the MAK reserved its harshest words for Aeroflot. The investigation identified major issues with Aeroflot’s training program, many of which stemmed from what the MAK considered to be a “bare minimum” attitude among Aeroflot’s training and management staff. In their view, following the letter of the regulations is not that helpful unless the airline also follows the spirit — specifically, by evaluating where the training program could better prepare pilots for actual operations, even if all the required elements are already present. Further, the MAK wrote, <em>“The flight crew training programs contained a number of provisions that allowed for ambiguous interpretations. Under such conditions, the airline’s management flight personnel, who were responsible for organizing initial and recurrent pilot training, ‘interpreted’ all ambiguities in the direction requiring less training.”</em></p><p>In the MAK’s opinion, Aeroflot’s training program should have identified and corrected Captain Yevdokimov’s flawed flare and landing techniques as a matter of course. It did not do so because of multiple serious problems, including high instructor turnover, which the MAK felt was the result of Aeroflot’s excessively rapid expansion of its SSJ-100 fleet. A poorly functioning safety management system also contributed.</p><p>Pitch down inputs during the flare can be a sign that the pilot lacks theoretical knowledge of the aircraft-sidestick control loop. With such understanding, a pilot can predict that a nose down pitch input at such a low altitude will cause an increase in descent rate that they will not have time to arrest before the plane hits the ground. An airline’s training program should not produce pilots who regularly and predictably make this kind of basic skill error.</p><p>In addition to issues of general piloting skill, the MAK strongly criticized Aeroflot’s training on flight in Direct Mode. I discussed many of the issues with this training back in Part 3, but the problems boiled down to the following:</p><p>- Despite frequent Direct Mode reversion incidents, Direct Mode was not taught as a standalone emergency during recurrent training, but rather as a secondary part of an unreliable airspeed emergency.</p><p>- During the accident flight, Captain Yevdokimov persistently left the aircraft out of trim, made dynamic/oscillatory sidestick inputs, and failed to manually deploy the spoilers, all of which are signs of poor theoretical and practical knowledge of flight in Direct Mode. And yet there were no comments on his training record from instructors regarding similar behavior during simulator sessions, indicating insufficient monitoring of his performance.</p><p>- In six other Direct Mode reversion incidents involving Aeroflot SSJ-100s, the pilots made similar basic handling mistakes, clearly indicating a systemic lack of preparation.</p><p>- Yevdokimov only reset the trim when he made a configuration change, suggesting that this was the only time he had been taught to trim, when in fact he needed to re-trim every time there was a significant change in airspeed or flight path angle.</p><p>In a dissenting opinion appended to the final report, Aeroflot hit back at many of these accusations. The airline argued that it was unfair to criticize the scope of its training program because it contained all the required items, which is horribly shortsighted and demonstrates exactly the type of problematic attitude described by the MAK. Aeroflot also stated that there was no evidence that there were any problems with Yevdokimov’s landing technique on previous flights, despite data demonstrating otherwise, and further argued that a pilot’s technique should be judged by the outcome, and because there were no exceedances of key parameters during his previous landings, clearly nothing was wrong. Once again, this is a shortsighted and naïve position.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IAQkYfEB4ZfQeVqwXu9VhQ.png" /><figcaption>Aeroflot’s dissenting opinion was typed up in a Microsoft Word document, or similar, with default settings. I don’t know why but I find that vaguely amusing. (MAK)</figcaption></figure><p>In addition to their incomprehensible statements about predictive windshear warnings, mentioned in Part 4, Aeroflot also defended its lax stabilized approach criteria and the policy of allowing pilots to ignore glideslope warnings after decision height, both of which the MAK considered unsafe. And regarding the spoilers, Aeroflot argued that the spoilers shouldn’t be deployed at first touchdown in Direct Mode because they impart a nose up moment that makes it hard to bring the nose gear down — despite the fact that the spoilers simultaneously help avert the much more serious risk of a bounce.</p><p>On the matter of weather, Aeroflot dismissed the notion that the pilots knowingly flew too close to a thunderstorm because the Vnukovo TDWR and the on-board weather radar weren’t calibrated to a common standard, and thus the MAK could not prove that the pilots saw red cells on their radar — even though the MAK tested this and found that the on-board weather radar display was more conservative than the TDWR and tended to show more red, not less.</p><p>After deflecting all blame from itself, Aeroflot decided to throw its fellow state-owned corporation UAC under the bus instead. Echoing Yevdokimov’s own statements, Aeroflot wrote that a reversion to Direct Mode should have been considered a “hazardous” rather than “major” failure because the degradation of performance is “significant” rather than “noticeable.” The airline argued that flying in Direct Mode is much harder for regular pilots than the MAK and the EASA test pilots believed, which is not a bad point, because as I stated in part 8.1, it’s relatively difficult to train a fly-by-wire pilot to transition flawlessly into Direct Mode. A “hazardous” designation would have required more redundancy to prevent an occurrence.</p><p>One other point made by Aeroflot that I do agree with is that the location of the trim switches is unergonomic, which ties into my argument about how the SSJ might have been better off with a Boeing-style trim system.</p><p>Lastly, Aeroflot blamed “the aircraft type design” for the collapse of the landing gear and ignition of the fire. In their view, the requirement to avoid “fuel spillage sufficient to constitute a fire hazard” could not be met using the testing criteria selected by UAC, even though those testing criteria met their own, separate set of requirements. Although I’m inclined to take the MAK’s position that this is more so a problem with the regulations themselves, it’s an argument that merits some consideration.</p><p>Overall, though, Aeroflot did itself a disservice with its dissenting opinion. The airline staked out several positions that are contrary to well-established best practices and failed to defend its flawed training process.</p><p>In its response to the dissenting opinion, the MAK revealed that it had spent a large portion of 2023 and 2024 carrying out additional tests at Aeroflot’s insistence, extending the investigation significantly, only for Aeroflot to reiterate the same tired concerns in its dissent. The MAK’s one page response went on to excoriate Aeroflot’s position on the causes of the accident, using the type of bureaucratic sarcasm that has always made the MAK stand out from the crowd. I’ll let the following quotation stand for itself.</p><p><em>“The author of the Dissenting Opinion proposes to exclude from the Conclusion section virtually all contributing factors associated with the organization of the flight operations and the establishment of the SMS at the airline, as well as with the crew’s adherence to standard operating procedures during the accident flight.</em></p><p><em>“Essentially, if one takes the Dissenting Opinion author’s point of view, it turns out that a crew trained in accordance with all applicable documents and standards, who had been debriefed in a proactive manner on all previous occurrences of Direct Mode reversion at the airline and trained in a simulator on these specific in-flight emergencies, pursuant to all effective FAR, OM, and SOP provisions, accidentally entered an area of thunderstorm activity, which resulted in the aircraft’s exposure to lightning and the reversion of the FBWCS to Direct Mode, and performed an approach without experiencing any issues with piloting or trim operation, during which they reasonably disregarded windshear and glideslope warnings, only to fail, at the moment of flare and landing, to control the aircraft and correct the deviations at touchdown, solely as the result of deficient aircraft stability and controllability properties in DIRECT MODE that were not identified in a timely manner during testing, as well as deficiencies in the manufacturer’s documentation.</em></p><p><em>“In fact, the author of the Dissenting Opinion suggests that the Commission should conclude that it identified no deficiencies causal to the accident in the organization of flight operations or the functioning of the SMS at the airline, nor in the flight crew actions. The Commission observes that the aforementioned stand by the author of the Dissenting Opinion is totally contrary to the established hard evidence presented in various sections of the Final Report, as well as to the results of the analysis conducted by the Commission, and is an overt defense of the </em>esprit de corps<em> of the interested party, represented by the author of the Dissenting Opinion.”</em></p><p>◊◊◊</p><p>Although MAK reports are notorious for including lengthy dissenting opinions from Rosaviatsiya and equally lengthy counter-opinions from the investigation commission, this accident was largely an exception. Rosaviatsiya did submit a dissenting opinion, as always, but it was only one page long and surprisingly bland compared to its past submissions. Despite the MAK’s heavy criticism of Rosaviatsiya’s failure to investigate several previous Direct Mode reversion incidents, the Rosaviatsiya representative didn’t attempt to defend against these accusations in their dissent. Instead, they only argued that the MAK should not conclude that the training program was inadequate to prepare the crew if it met the minimum regulatory requirements; and that the contents of the Rosaviatsiya-approved training program were not the cause of the pilots’ handling difficulties, for which they blamed Aeroflot’s failure to instill basic pilot competencies. In its response, the MAK dismissed these arguments but accepted Rosaviatsiya’s proposed recommendation that aircraft manufacturers clearly establish which types of emergencies must be practiced individually instead of in concert with another emergency.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*LvBvnR0LCJYLOvHO.jpg" /><figcaption>A memorial to one of the victims of the crash of flight 1492. (Lev Feodoseyev)</figcaption></figure><p>◊◊◊</p><p>What I wanted to convey in this final chapter is that despite widespread reductive speculation, the accident was not solely caused by the pilot, the airline, or the airplane. Instead, the accident was the result of a convergence of numerous deficiencies associated with all three, none of which were causal by themselves, but were causal in concert. Furthermore, the breadth and depth of the deficiencies identified in this investigation was such that it calls into question the safety of Russia’s entire aviation sector. The issue isn’t really that rules were being violated; in fact, relatively few causal or contributory factors were the result of overt regulatory violations. Instead, the issue is that Russian civil aviation is afflicted by an attitude problem — a lack of curiosity, a lack of willpower, and a lack of interest in the goal of safety itself. Every involved party, from the pilots to Aeroflot to UAC to Rosaviatsiya, at least vaguely tried to follow some of the rules, but no one expressed any <em>ambition.</em> Most people were just going through the motions.</p><p>I know as a matter of personal experience that there are many people in Russia who are genuinely dedicated to doing things right, and I have no doubt that many of them work in the aviation industry. Granted, many of the best have left since 2022, but plenty remain. The problem is that apathy has been enshrined on an institutional level, trapping the people who care under the weight of those who do not, or who choose not to for purposes of survival. Such a culture is not easily rooted out.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*liCmINAOUAofQycL" /><figcaption>22-year-old crash victim Jeremy Brooks, pictured, was on his way to start his dream job as a fly fishing guide in the Kola Peninsula. He graduated from the same small liberal arts college that I attended, and was a member of the graduating class ahead of mine. Old coworkers of my dad knew his parents. For all I know I might have passed him in a hallway on the way to class. The point is that every death ripples outward across families, across regions, across national barriers, magnifying itself a hundred times. To not do one’s utmost to prevent that — that is unfathomable to me. (Brooks family)</figcaption></figure><p>The MAK’s final report contains 49 recommendations to improve everything from simulator record-keeping to the location of the SSJ’s on-board megaphones. Many of these recommendations directly address the deficiencies described throughout this article. But despite the passage of more than 6 years since the crash, the section of the report listing safety actions taken to date contains only one entry, concerning an update to Russia’s USSR-era airport fire rescue standards. This is an abysmally inadequate response. Where is the outrage? Where is the commitment to “never again”? How many times will I have to write about people perishing in a Russian aircraft because nobody cared about doing it right? How long will airlines and manufacturers and Rosaviatsiya keep up their circular finger-pointing exercise, just to maintain the illusion that it’s the other guy who needs to change? Until the next accident I suppose — and what then?</p><p>In an increasingly isolated Russia, my words as a foreigner mean less than nothing. And from the other side, a few might criticize me for caring about Russian airline safety at all. But I still think this is a story that should be told, because it was a real thing that happened to real people in a real place, and even if that story disappears into Russia’s apathetic churn, perhaps we can make something of it here.</p><p>_______________________________________________________________</p><p><em>Dear readers — I couldn’t have conducted this far-reaching, at times exhausting research and writing project without your </em><a href="https://www.patreon.com/Admiral_Cloudberg"><em>support on Patreon.</em></a><em> This article took countless hours of work, a lot of late nights, and an unhealthy amount of sour gummy candies to finish. I probably cried at least a couple times; I’ve lost track. My gratitude to all of you is endless. — Kyra</em></p><p>_______________________________________________________________</p><p><em>Don’t forget to listen to Controlled Pod Into Terrain, my podcast (with slides!), where I discuss aerospace disasters with my cohosts Ariadne and J! </em><a href="https://www.youtube.com/@ControlledPodIntoTerrain"><em>Check out our channel here</em></a><em>, and listen to </em><a href="https://www.youtube.com/watch?v=-i3dZNFDk84"><em>our latest episode about a titanic battle between a BAC 1–11 and some wind.</em></a><em> Alternatively, download audio-only versions via </em><a href="https://rss.com/podcasts/cpit/"><em>RSS.com</em></a><em>, or look us up on Spotify!</em></p><p>_______________________________________________________________</p><p><a href="https://www.reddit.com/r/CatastrophicFailure/comments/1kld96e/2019_the_crash_of_aeroflot_flight_1492_a_sukhoi/">Join the discussion of this article on Reddit</a></p><p><a href="https://www.patreon.com/Admiral_Cloudberg">Support me on Patreon</a> (Note: I do not earn money from views on Medium!)</p><p><a href="https://bsky.app/profile/kyracloudy.bsky.social">Follow me on Bluesky</a></p><p>Visit <a href="https://www.reddit.com/r/AdmiralCloudberg/">r/admiralcloudberg</a> to read and discuss over 260 similar articles</p><p><a href="https://docs.google.com/document/d/1OMShOX-c-IJRssSveFiH9WpstC5po_hBQkqmH9c5tyM/edit?usp=sharing"><strong>Bibliography</strong></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=ee61cebcf6ec" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Acids to Ashes: The crash of Pan Am flight 160]]></title>
            <link>https://admiralcloudberg.medium.com/acids-to-ashes-the-crash-of-pan-am-flight-160-bed699b6b8b2?source=rss-e119a26506e3------2</link>
            <guid isPermaLink="false">https://medium.com/p/bed699b6b8b2</guid>
            <category><![CDATA[technology]]></category>
            <category><![CDATA[logistics]]></category>
            <category><![CDATA[aviation]]></category>
            <category><![CDATA[flying]]></category>
            <category><![CDATA[history]]></category>
            <dc:creator><![CDATA[Admiral Cloudberg]]></dc:creator>
            <pubDate>Fri, 28 Mar 2025 04:33:21 GMT</pubDate>
            <atom:updated>2026-01-07T06:05:56.187Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*ZJrkK_Nx1zzjKf9K.jpg" /><figcaption>The burnt wreckage of Pan Am flight 160 lies next to the runway at Boston Logan Airport. (FastStone/Vintage Image Photos via eBay)</figcaption></figure><p>On the 3rd of November 1973, the crew of a Pan Am cargo plane lined up to land at Boston’s Logan International Airport, struggling desperately to reach the runway as a fire raged in the cargo deck and smoke filled the cabin. But just moments from touchdown, the aircraft appeared to sway wildly from side to side before it abruptly dived into the runway threshold, spewing burning debris across Logan’s runway 33 Left. None of the three crew survived to explain why.</p><p>The investigation into the crash revealed a sequence of events that touched multiple areas of the aviation industry, from supply line confusion involving a massive shipment of corrosive chemicals, to the design assumptions built into the Boeing 707’s firefighting procedures, to crew resource management issues, as the flight engineer turned off critical control systems without the captain’s knowledge. Piecing the details together wasn’t easy, even with the help of the sometimes vague NTSB report. But while some questions remain incompletely answered, the story of Pan Am flight 160 nevertheless highlights the fallacy underlying several safety assumptions that were not properly questioned until the <a href="https://admiralcloudberg.medium.com/alone-in-the-inferno-the-crash-of-ups-airlines-flight-6-507d13f3e481">crash of UPS flight 6</a> in 2010. In fact, those very parallels are part of what make this obscure 50-year-old accident worth revisiting — because some of the mistakes that brought down flight 160 transcend the time period in which they occurred.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*faF5BHL3d-8nm84j.png" /><figcaption>N458PA, the aircraft involved in the accident, pictured in 1971. (AeroIcarus via Flickr)</figcaption></figure><p>Between 1956 and 1983, Pan American World Airways, the de facto flag carrier of the United States at the time, operated a cargo division specializing in international freight transport to and from the US. During the 1960s and 1970s, the workhorse of the Pan Am Cargo fleet was the -320C variant of Boeing’s first jet airliner, the four-engine 707. The 707–320C had a strengthened floor and a new cargo door to permit cargo-only operations, with a cabin that was fully convertible between passenger and cargo configurations, as well as intermediate or “combi” formats. However, the 707 that starred in this particular story was configured for cargo only.</p><p>That aircraft, with registration N458PA, was manufactured in 1967 and had been in service for 6 years when it arrived at the cargo loading ramp at New York’s John F. Kennedy International Airport on the 3rd of November, 1973. Its next scheduled trip was flight 160 to Frankfurt, Germany, with a stop at Glasgow Prestwick Airport in Scotland, where personnel were to offload several pallets of material bound for the National Semiconductor manufacturing plant in nearby Greenock.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/612/0*tKZ0eGf0mcxJ1kP4" /><figcaption>The headquarters of National Semiconductor in Santa Clara. (Bloomberg via Getty Images)</figcaption></figure><p>Now a division of Texas Instruments, the National Semiconductor Corporation, or NSC, was a major independent manufacturer of semiconductors and related analog devices, headquartered in Santa Clara, California.</p><p>The semiconductor manufacturing process involves a laundry list of caustic chemicals with scary names that I won’t enumerate, but it’s a fact of our modern world that sometimes these chemicals have to be transported from one place to another. And it was also a fact that sometimes NSC needed to buy chemicals in America for later use at its Scottish facility. It would be possible to ship them by water, but in a high-tech industry like semiconductors, putting the materials on a cargo ship is sometimes too slow, so only an airplane will get the job done in time. And for this particular mission, who else but Pan Am?</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/874/0*uXQJ91UfhKREwfcI.jpg" /><figcaption>A 1949 Allied Chemical sales catalog. (Amazon.com)</figcaption></figure><p>In September and October 1973, NSC placed several orders for various chemicals from the Allied Chemical Corporation, or ACC, which is now part of Honeywell.* ACC acted as a one-stop-shop to buy chemicals that were mostly manufactured by other companies. The chemicals in NSC’s orders that were bound for the Scotland plant via Pan Am flight 160 included but were not limited to butyl acetate, stripping solution A-20, isopropanol, hydrogen peroxide, xylene, acetone, nitric acid, methanol, hydrofluoric acid, sulfuric acid, and glacial acetic acid. In its order request, NSC specified that the chemicals needed to be properly packaged for air transport, an area where ACC needed outside assistance. Given the large number of chemicals in its inventory, the company didn’t necessarily have the expertise on hand to safely repackage every chemical for every mode of transport.</p><p>An ACC manager subsequently attempted to engage another chemical company to repack some of the chemicals that were stored in containers that exceeded the maximum quantity restrictions for air transport. However, the other company, which was not named in the report, replied that they were “not interested.” My understanding is that repacking these chemicals into smaller containers is a rather complex and potentially dangerous process, and this third company probably decided that the liability wasn’t worth it.</p><p>On October 25, ACC advised NSC that while they were aware that the chemicals would be shipped by air, they would nevertheless be packaged for surface transport. Now, this is where matters become slightly confusing.</p><p>To understand why, we need to talk about nitric acid, which is the chemical of primary interest to this story. Nitric acid (HNO3) is a corrosive mineral acid and an oxidizer that will react with a wide variety of substances, producing heat and oxygen as byproducts. It therefore presents not only a corrosion risk but also a fire risk — in fact, even though the acid itself isn’t flammable, it’s such a powerful oxidizer that some fuels will ignite immediately upon contact with it. For this reason, in 1973 federal regulations required that bottles of nitric acid intended for transportation <em>“be placed in tightly closed metal containers, and well cushioned therein on all sides with incombustible mineral packing material, such as whiting, mineral wool, infusorial earth (kieselguhr), asbestos, sifted ashes, or powdered china clay, etc.”</em></p><blockquote>*Actually, AlliedSignal, the successor of ACC, acquired Honeywell and adopted its name, not the other way around. I have to put this in here because my readers are pedants. I say that with love.</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/753/0*PSpMVvFlHXaKsQpq.jpg" /><figcaption>A bottle of nitric acid, with warning labels. (Post Apple Scientific)</figcaption></figure><p>Neither the NTSB report nor the reproduced text of the regulation states what type of transportation the above packaging was required for. I was also unable to find the original version of the federal hazmat regulations that were in force at the time. It appears most likely, from context, that these regulations did apply to transport of nitric acid by air, and the NTSB report states that there were generally few differences between the packaging requirements for chemicals shipped by cargo plane and those shipped by freight rail. However, any differences between packaging requirements for aircraft versus truck transportation are not mentioned in the report. Since ACC intended to ship the nitric acid to Pan Am’s JFK loading facility via truck, it can be presumed that when the company said it would package the nitric acid “for surface transport,” it was following or attempting to follow the packaging regulations for truck transportation. However, I was not able to find these regulations or establish whether they differed from air transport packaging requirements in any way.</p><p>One might presume that the main difference was the container size — after all, ACC had tried and failed to find a contractor who could repack some chemicals whose containers exceeded the maximum unit volume for air transport. However, according to the Pan Am flight 160 cargo manifest, the nitric acid was stored in 5-pint bottles, which are smaller than the maximum per-container quantity of 2.5 L prescribed by current US hazmat regulations for air transport. This volume presumably was within limits in 1973 as well, although this is not explicitly discussed in the NTSB report. Therefore, it remains unclear what ACC meant when it said it would package the nitric acid for surface transportation but not for air transportation.</p><p>It is also not precisely known, or at least the NTSB report does not make it precisely known, how ACC originally packaged the nitric acid, except that the acid was stored in glass bottles with plastic screw-on caps. It is known that the bottles were not placed in metal containers as required by the hazmat regulations for air transport. I wasn’t able to determine whether such containers were required for truck transport at the time. What materials were used to cushion the bottles at this stage, if any, is also not stated in the report. However, we’ll come back to that topic in a moment.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/819/0*bih8eq4crHe0K4ff" /><figcaption>Santini Brothers delivery trucks, pictured… sometime prior to 2001. (Seven Santini Brothers on Facebook)</figcaption></figure><p>To deliver the nitric acid and other chemicals from its facility in southern California, ACC contracted the trucking company P. Calahan Inc. to transport the goods to Maspeth, New York, where they were to be deposited at a “repacking and trucking facility” owned by the logistics company Seven Santini Brothers. NSC had verbally contracted Santini to repackage the chemicals before transferring them to the Pan Am cargo loading facility at JFK Airport. It isn’t explicitly stated why this was done but I presume that NSC’s intention was for Santini to upgrade the packaging to meet air transport requirements after learning that ACC would not do so. At this point Santini should probably have asked NSC for detailed handling instructions, but they didn’t, and even if they had, NSC’s traffic manager possessed no such information anyway.</p><p>When the nitric acid and other chemicals arrived at the Santini facility, the Santini office manager consulted the International Air Transport Association (IATA) Restricted Articles Regulations in order to determine what types of packaging and labeling would be needed. He did not appear to be aware that IATA rules, while helpful, carried no legal force in the United States, and that FAA and Department of Transportation regulations had to be consulted as well. Nor did he appear to understand much of anything else about transporting hazmat.</p><p>Here is where we have to come back to the question of how the nitric acid bottles were cushioned, and by whom. What we know for sure is that by the time the bottles reached the aircraft, they were cushioned with sawdust, which clearly doesn’t meet the regulatory requirement that nitric acid bottles be packed with an “incombustible” cushioning material. So who put the sawdust there? The NTSB report is somewhat open to interpretation on this matter.</p><p>When discussing the packaging worksheet put together by the Santini office manager, the NTSB report states, <em>“it was presumed by the packer that if [sawdust] was ‘OK’ for red label materials, it was ‘OK’ for white label materials.” </em>So what does that mean?</p><p>There are several possible meanings of “red label” and “white label,” and the NTSB report doesn’t clarify which.</p><p>The most obvious possibility is that these terms refer to Interstate Commerce Commission (ICC) labels, which are the ancestors of today’s Department of Transportation (DOT) labels, and which were in use in 1973. These labels were explicitly known by the terms “red label,” “white label,” “yellow label,” and so on, with “red label” referring to flammable liquids and flammable compressed gases, while “white label” referred to acids and corrosive liquids. If this system was the source of the confusion, then the packer must have believed that some or all red label materials could be packaged with sawdust, and that the constraints on red label materials were greater than those on white label materials.</p><p>However, I haven’t been able to verify that the hazmat regulations extant in 1973 permitted the use of sawdust for any red label materials. So far, the latest pre-1975 version of the ICC hazmat transportation regulations that I have been able to find dates to 1918, making it a mere distant ancestor of the regulations used by the packer in 1973. The 1918 regulations did permit the use of sawdust as a packing material for some red label materials, and they also stated that when red label and white label materials were carried in the same package, the package should be given a red label — which carries the implication that red labels are stricter than white labels. (The 1918 regulations did also state that sawdust was not an acceptable packing material for white label acids.) If similar language still existed in 1973, then confusion stemming from ICC labels seems plausible, but I was unable to confirm this.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/488/1*y9A0A-SYZmQbm3dYwmGUFw.png" /><figcaption>The NFPA 704 diamond for nitric acid. (Fischer Scientific International)</figcaption></figure><p>Another possibility is that “red label” and “white label” refer informally to two of the four NFPA 704 label colors that are used to quickly convey information about the type of hazard posed by a chemical, as the NFPA 704 labeling system also existed at the time of the accident.</p><p>Appearing in a diamond shape, the four NFPA 704 colors — red, blue, yellow, and white — indicate, respectively, the chemical’s flammability, hazard to health, reactivity, and any other special properties it may possess. The red, blue, and yellow labels are accompanied by a number on a scale from 0–4 indicating the seriousness of the threat. The white label conveys other information using one of a small number of special symbols, including OX for an oxidizer.</p><p>It would be somewhat strange for the report to refer to “red label materials” or “white label materials” when discussing NFPA 704, since all four colors always appear on the label and it’s the number or symbol that indicates the level of danger. There is some anecdotal evidence that these terms have been used informally to refer to NFPA 704, but I can’t confirm this. Furthermore, this statement isn’t a direct quotation from any of the individuals involved, and it might have been mangled somewhere between the packer’s original understanding and its description in the NTSB report. In either case, however, an intriguing explanation makes itself apparent.</p><p>The issue is that nitric acid will happily react with the organic compounds in sawdust to produce heat and oxygen that then combine to set the sawdust on fire. However, because the acid itself isn’t flammable, its NFPA 704 red label has a value of zero, indicating “not flammable.” Therefore, it’s plausible that the packer knew sawdust was an approved cushioning material <em>for substances with an NFPA red value of zero</em>, and consequently believed that sawdust was an approved cushioning material for nitric acid bottles, even though the white label indicated that nitric acid is an oxidizer. To date, this is the most plausible explanation I’ve come up with for why someone would think sawdust was okay for this purpose.</p><p>But even then, we’re still left with another glaring question: who was the “packer” who made this mistake? Unfortunately, the NTSB report isn’t clear about this matter either. One possibility was that “the packer” referred to Santini. But I think the evidence actually suggests that the packer who became confused about labels was ACC itself.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*aE76rlNuaXtpO5Q8JZwTsA.png" /><figcaption>Obligatory excessively convoluted diagram showing how I deduced that ACC was the one who originally packed the nitric acid with sawdust and Santini was not. (Own work)</figcaption></figure><p>On this matter, a crucial line in the report states, <em>“Since Santini did not stock noncombustible cushioning material and had no metal cans to encase the nitric acid, the Lyon representative was contacted.”</em> The middle part of this line makes it clear, as I stated earlier, that ACC placed the nitric acid bottles directly in the boxes without intermediate metal cans before sending them to Santini. Otherwise there would have been no need for Santini to provide its own metal cans.</p><p>However, the first part of this line has multiple interpretations. First of all, if Santini was contacting a third party for advice because they didn’t have noncombustible cushioning materials, it follows that the Santini office manager knew or suspected that noncombustible cushioning material was required to pack the nitric acid. Furthermore, one of three possibilities must be true: 1) the nitric acid as received by Santini was already cushioned in sawdust; 2) the nitric acid was received without cushioning material at all; or 3) the nitric acid was received with noncombustible cushioning material, but Santini was unable to reuse the material. We know that one of these must be the answer because if the nitric acid had arrived with reusable, noncombustible cushioning, then the fact that Santini didn’t have noncombustible cushioning was irrelevant.</p><p>Now, before trying to determine which of these possibilities is most likely, we need to explain who Lyon was and what they told Santini. This third party was Lyon Commercial and Export Packing Division, which had been contracted by NSC to pick up and pack 60 boxes of sulfuric acid from ACC in southern California. Lyon had then delivered the boxes to Burlington Northern Air Freight, which packaged them for air transport and handed them to TWA, which flew them to JFK. Lyon wasn’t involved in shipping any of the chemicals that ended up at Santini, but apparently they were being used as a point of contact. And when the Santini office manager telephoned Lyon for advice about the nitric acid, the Lyon representative told him that it was perfectly fine to omit the metal canisters and use sawdust as packing material. This was completely, wildly, pants-on-fire false. However, the office manager did what he was told, and the repackaging worksheet given to the floor personnel consequently instructed them to place the glass bottles of acid directly into the wooden boxes and cushion them with sawdust.</p><p>This phone call is quite clearly the reason why Santini believed sawdust was an acceptable cushioning material. However, if we follow possibility 2 (the nitric acid was received without cushioning material) or possibility 3 (the nitric acid was received with noncombustible cushioning material that could not be reused), then Santini is the party that first introduced the sawdust, and therefore must also be the “packer” who thought sawdust was okay because of confusion over red and white labels, whether ICC or NFPA 704. But that’s not why Santini thought sawdust was okay — they thought that because Lyon told them it was. So Santini can’t be the “packer.” And the “packer” can’t be Lyon because they didn’t pack the nitric acid at any point. So the packer who was confused about labels <em>has to be ACC, </em>and therefore the answer must be possibility 1 (the nitric acid as received by Santini was already cushioned in sawdust).</p><p>As for why ACC, a chemical distributor, would make this mistake, it’s easier than you might think. Today, people involved in handling hazmat can refer to the Material Safety Data Sheet for detailed instructions, but the MSDS wasn’t created until 1983. And remember, ACC didn’t manufacture most chemicals — they had an inventory of thousands of chemicals manufactured by other people. So one can imagine a poorly trained floor employee misreading the NFPA 704 or ICC and packing nitric acid in sawdust because the little diamond said it wasn’t flammable. The bottles cushioned in sawdust were then shipped across the country to Santini, where the office manager saw them, thought “that’s weird, shouldn’t the cushioning be noncombustible,” and then called Lyon, who told him it was fine as-is.</p><p>None of the information in the above paragraph is clearly or directly stated in the NTSB report. However, I think it’s the most likely explanation for what happened, based on the available evidence.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2hmVpjuOFzjChK-q2eO8CQ.png" /><figcaption>The cargo deck layout of the accident aircraft. (NTSB)</figcaption></figure><p>Working from the office manager’s instructions, Santini personnel constructed wooden boxes according to the specified federal standard, placed the nitric acid bottles and sawdust cushioning into the new boxes, and organized the boxes onto pallets for transportation by truck to JFK. Santini did not affix labels stating “corrosive liquid,” “cargo aircraft only,” and “this end up,” even though these were specified in the IATA rules used by the office manager to create the packaging worksheet. In this condition, the nitric acid and other chemicals were taken to the Pan Am loading dock on November 2nd, the day before flight 160’s scheduled departure, where the shipment was united with the sulfuric acid shipment from TWA.</p><p>The chemicals purchased by NSC represented only part of the cargo to be carried on flight 160. Out of 24,000 kg of cargo, only about 7,000 kg were restricted chemicals; the rest consisted of various merchandise, machinery, and mail, which collectively occupied 10 out of the aircraft’s 13 available cargo loading positions. Pan American attempted to organize the shipment onto three pallets to fit the remaining three positions, but the loaders discovered that not all of the chemicals would fit on three pallets. This was probably because the sulfuric acid was supposed to have been shipped via TWA on October 31st but was bumped to flight 160 at the last minute after the required space failed to materialize. To correct the issue, the loaders removed some items from a fourth pallet and replaced them with several boxes that may have contained sulfuric acid.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*aS2wuXvJivectwAe" /><figcaption>Cargo pallets and containers ready for loading onto a Lufthansa Cargo B707. Note how the top of each pallet gets narrower at the top to fit into the cylindrical fuselage. (Lufthansa Cargo)</figcaption></figure><p>But when Pan Am ramp workers tried to load the three remaining pallets onto the aircraft, they found that the outer edges of the upper tier were not sufficiently contoured to fit into the 707’s cylindrical fuselage. If the stack of boxes on the pallet is too square, the upper corners won’t fit through the opening, which is exactly what happened in this case. So in order to make the topmost tier of each pallet narrower, the supervisors on duty instructed the cargo loading personnel to turn some boxes on the topmost tier sideways. Although the nitric acid boxes did have small arrows pointing upward on each face, recall that Santini hadn’t affixed them with the required “this end up” labels. And considering that there were no less than 160 nitric acid boxes in the NSC shipment, amounting to almost half the total, it was virtually certain that some of the boxes that were upturned by the Pan Am cargo loaders contained nitric acid.</p><p>The first shift to work on the pallets bound for flight 160 didn’t quite finish the job, and when the second shift arrived to find boxes on their sides, one employee became concerned and took the issue to a supervisor. However, the supervisor told the employee to leave the boxes that way, and the matter was closed. A short time into this second shift, the pallets were finally wrapped and covered, and a walkaround inspection identified no spillage or unusual smells. The pallets were then loaded onto the 707’s main deck.</p><p>According to federal regulations, flight crews must be notified of any restricted cargo aboard their aircraft so that they can use this information for things like emergency decision-making and notifying fire crews. These regulations specified that the dispatcher or person in charge of cargo palletization must sign a notification document listing the amount and type of hazmat on the aircraft, which was to be presented to the captain by the loadmaster. The captain was required to sign the notification, demonstrating their acceptance of the cargo (or, should the captain identify some problem with the hazmat, this would provide a final opportunity to reject the shipment).</p><p>In the case of Pan Am flight 160, the hazmat notification was signed by the dispatcher, but was never given to the loadmaster, who was only barely aware that there was hazmat on board at all. Instead, the notification was handed to another unspecified individual, who claimed that he presented it to the captain, then left the documents aboard the aircraft. But while one page from this notification was later found in the wreckage after the accident, the captain’s signature wasn’t on it — and as we will soon see, the actions of the crew during the flight did not suggest that they were aware of the hazmat lurking in the main deck cargo area.</p><p>◊◊◊</p><p>The crew of Pan Am flight 160 consisted of two pilots and a flight engineer, led by 53-year-old Captain John Zammett, a highly experienced airman with over 16,400 flying hours, including over 5,800 on the Boeing 707. The first officer was 34-year-old Gene Ritter, who had been flying for Pan Am since 1966, accumulating a total of 3,843 flying hours, all of them on the 707. And lastly, the flight engineer was 37-year-old Davis Melvin, who had over 7,200 hours, including 3,260 on the 707. Without going into excessive detail, it suffices to say that this was a crew who knew the 707 inside and out.</p><p>At 08:25 local time, flight 160 took off from JFK and headed northeast across New England and Canada. For the first half an hour, there was no sign of trouble. But the apparent quiet belied the dangerous situation developing on the cargo deck.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*z4EhmHG1PvDJeG6v6zHEXw.png" /><figcaption>Photos from the NTSB’s nitric acid + sawdust test. (NTSB)</figcaption></figure><p>The NTSB could only guess at what exactly happened, but the theory goes as follows. Most likely, the caps on the nitric acid bottles were screwed shut at sea level, with no pressure differential between the inside and outside of the bottle. But while the 707’s main deck is pressurized, it’s not pressurized to sea level, so as flight 160 climbed, a pressure differential would have developed between the inside and outside of each bottle. This wouldn’t have been a problem in bottles that were stored upright, due to the layer of air between the top of the acid and the bottom of the lid. But if a jar was turned sideways with the acid directly against the lid, and the lid was only “sea level tight,” then the pressure differential could have forced some of the nitric acid out the bottle through tiny gaps under the seal. If you’ve ever driven up a mountain with a reusable water bottle, and it started squealing and foaming, that’s the same phenomenon.</p><p>If nitric acid began to leak in this manner, it would have come into direct contact with the sawdust cushioning material due to the lack of intermediate metal canisters. In NTSB tests, sawdust exposed to nitric acid began to produce white smoke after 7 minutes, and flames became visible after 19. Two minutes after that, the flames escaped from the box. At that point, if the box had been aboard a real cargo plane, the fire would have become uncontrollable.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AsBnCgp0Rd2x9b2bN1sGFA.png" /><figcaption>An overview of the main deck cargo smoke detector system on the 707–320C. (Caledonian Airways via Classic Jetliners Forum)</figcaption></figure><p>At some point as flight 160 was climbing to its cruising altitude of 31,000 feet, one of the upturned nitric acid bottles most likely leaked into the sawdust, triggering a reaction that generated heat and oxygen until something caught fire.</p><p>Although the 707–320C was equipped with main deck smoke detectors, the NTSB found that they didn’t provide early warning of the fire, for unknown reasons. The smoke detectors on the 707 were a primitive design in which air from the compartment was physically drawn past a window in the flight engineer’s station, where smoke particles were illuminated by an indirect light source, creating the impression that the window was lit. A small pinhole above the window allowed the flight engineer to check whether the indicator bulb was working. Unfortunately, this setup was much less reliable than a smoke detector located in the compartment itself, and there are many plausible reasons for its failure to provide a timely warning.</p><p>The cockpit voice recording only captured the last 30 minutes of the flight, which didn’t include the pilots’ initial observation of smoke. Rather, the first conversation on the CVR consisted of Captain Zammett calling the Pan Am operations department for advice. “Ah, yes sir, we have ah, accumulation of smoke in the lower 41 and we’re gonna go back to Boston. Do you want us back in Boston or back in New York?”</p><p>“Ah, standby 160, we’ll find out,” Operations replied.</p><p>The “lower 41” was a term used by 707 pilots to refer to the avionics bay, which was located underneath the forward galley and aft part of the cockpit. The cramped compartment could be reached by a crew access hatch in flight. It was also connected to the cockpit by a floor vent designed to prevent a pressure differential from developing between the two spaces. Cooling air to the avionics was supplied by a cooling fan that also drew air down from the cockpit into the compartment.</p><p>If the crew thought the lower 41 was the source of the smoke, then it must have been because it was the first place they saw smoke, probably swirling about near the floor vent. It is known that this smoke came from the fire in the main cabin, but how it got there is somewhat unclear from the NTSB report. According to the 707–320C operations manual, airflow into the underfloor avionics bay comes from the cockpit and is exhausted either directly from the compartment via the electronic cooling air valve, or indirectly via ducts leading around the outside of the forward (lower) cargo compartment and out through the forward outflow valve. I wasn’t able to find any reference to a normal airflow path from the main deck into the lower 41 that could have caused smoke to be drawn there.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*53-7oNcikB5pxYFULwfVbg.gif" /><figcaption>A detailed diagram of the B707–320C, for your enjoyment. (Charles Kennedy, “Boeing 707 Owners’ Workshop Manual: 1957 to present”)</figcaption></figure><p>The NTSB report states that during post-accident smoke tests, <em>“airflow was observed to move downward through the barrier smoke chute into the lower 41.”</em> The “barrier” appears to refer to a “smoke barrier” installed between the main deck cargo area and the crew rest area behind the cockpit. However, I wasn’t able to find any reference to this barrier or a “smoke chute” anywhere in the operations manual, and the location, nature, and purpose of these components was not explained in the NTSB report.</p><p>Furthermore, an annex to the report states, <em>“The Boeing Company has issued [a] Service Bulletin… which permits installation of a smoke chute in the passenger-cargo configuration similar to that used in the all-cargo configuration. The cargo compartment in the passenger-cargo configuration is ventilated down through the cabin floor forward into the lower avionics area.”</em> This line is also not explained, and doesn’t reflect what I read in the operations manual, but the manual was from a different airline and might not have matched 1:1 to the configuration used by Pan Am.</p><p>The above quote appears to refer to a 707 “combi” configuration where the main deck is divided into a cargo area in the front and a passenger area in the rear. In an all-passenger configuration, air in the cabin flows toward the rear and out the rear outflow valve, but in a combi format, one would not want smoke from a fire in the cargo area to flow aft into the passenger area, so it makes sense that an alternate route would be established to ventilate the cargo area downward through the lower 41 and out the forward outflow valve instead. The above quotation also shows that this vent configuration was used on cargo-only versions of the 707–320C, which could include the accident aircraft.</p><p>From the above information, I would hazard a guess that the smoke chute was intended to evacuate smoke from the main deck overboard via the lower 41 avionics compartment. This would also explain the references to a “barrier,” as such a chute would form part of a smoke barrier system designed to keep smoke out of occupied areas. But while this is one plausible interpretation of the information in the report, I’m still not 100% certain that it’s correct.</p><p>Regardless of the answer, it remains true that as the fire spread through the main cargo deck on Pan Am flight 160, smoke made its way into the lower 41, where it was seen by the crew through the pressure relief vent prior to any formal indications from the smoke detectors. We know that if the main deck smoke detectors had illuminated first, then the crew probably wouldn’t have reported that the lower 41 was the source of the smoke. They also might have suspected that the smoke came from the main deck if they had been properly notified of the nature and quantity of the hazmat on board. But because neither of those things happened, they quickly developed an incorrect mental model of where the fire was located.</p><p>The fact that the crew believed the smoke was coming from the avionics compartment turned out to be crucial to the sequence of events. If electronic equipment in the lower 41 was overheating or malfunctioning, then the source of smoke could be identified, isolated, and eliminated. But if there was a fire burning in the main cargo deck, there was little the crew could do about it, and there would be a correspondingly higher level of urgency.</p><p>In their initial communications, the level of urgency displayed by the crew was rather low. At first, Captain Zammett and First Officer Ritter discussed the possibility of flying all the way back to New York, which would not be a reasonable course of action if they believed they were in an emergency. Zammett also said to Flight Engineer Melvin, “You don’t think you could get down there and spot that, huh,” suggesting that he climb into the lower 41 and try to figure out what was burning.</p><p>“I can’t get around down there at all, I — I don’t see any reason why that ####*, it should’ve popped a breaker by now. It ought to short out somewhere,” said Melvin. In his opinion, electrical smoke in the avionics bay should be associated with a tripped circuit breaker, which was an apt assessment. Unfortunately, this evidence didn’t cause the crew to question whether the fire was actually in the lower 41 — a classic form of psychological bias.</p><p>*<em>In the CVR transcript, the # symbol represents an expletive that was redacted. In previous articles, I sometimes attempted to guess what expletive was used based on context in order to make the text flow better. However, I’ve decided not to do this anymore.</em></p><p>First Officer Ritter now jumped in with a suggestion. “Can we increase our airflow so we get rid of some of the smoke through the outflow valves and equipment cooling circuit?”</p><p>“Yeah,” someone said.</p><p>“Just stick your head down there and see if it’s still coming,” Captain Zammett suggested to the flight engineer.</p><p>At 09:06, the Boston air traffic control center, still unaware of the situation, instructed flight 160 to contact Montreal center as the aircraft crossed the border into Canada. Seconds later, Pan Am operations stated that they would prefer the flight to return to New York, as opposed to Boston.</p><p>As First Officer Ritter worked out their turn back to New York with Boston and Montreal, Flight Engineer Melvin continued to watch the smoke drifting up into the cockpit from the floor vent. “This # sure is coming, John,” he said to the captain. “Lemme see if I can shut this, ah, blower off. I’m gonna raise the cabin up — up to ten thousand?”</p><p>Melvin’ appeared to be following the emergency Smoke Evacuation procedure, on which the second item, after optionally donning oxygen masks, was to reduce the cabin pressure to the equivalent of 10,000 feet altitude. This would cause air to flow out of the cabin and cockpit faster, hopefully reducing the smoke.</p><p>“Try that,” said Captain Zammett.</p><p>“Could open a bleed and try to get some air in this ####,” Melvin added, referring to the next item on the checklist, which was to set the bleed valves to “maximum on” in order to increase airflow into the cabin and cockpit. This action would complement the previous step, which was to increase airflow out.</p><p>“Go ahead,” said Zammett.</p><p>On the radio, First Officer Ritter finally established contact with Montreal and stated their intention to return to New York. “Turn right heading one eight zero,” Montreal replied.</p><p>In the cockpit, the smoke wasn’t going away. “It’s still getting thicker, isn’t it?” Zammett asked.</p><p>“Seems like there could be equipment…” Melvin started to say.</p><p>“There is no smoke in those detectors though, is there?” Zammett asked.</p><p>“Well, there is now,” said Melvin. Apparently enough smoke had finally reached the main deck smoke detection windows to give him an indication.</p><p>“There is?” said Zammett.</p><p>“Yeah.”</p><p>“Where would that pick it up from?” Zammett wondered. “Back there, or…?”</p><p>“Well, it’s probably going up this way and coming back around,” Melvin said, suggesting that the smoke in the main deck must have come from the lower 41 via the cockpit. In fact, it was the other way around, and this statement marked another example of confirmation bias at work.</p><p>“Turn the equipment cooling blower off,” Melvin said. “I think you don’t need to go in the back then.” Normally, a main deck smoke indication would prompt one of the pilots to check the main deck, but since they had convinced themselves they already knew the source of the smoke, they decided not to.</p><p>“Right,” said Zammett.</p><p>“Because it should pop a breaker someplace,” said Melvin.</p><p>“Yeah.”</p><p>“We ought to go on oxygen, this #’s getting a little thick, eh?” Melvin added.</p><p>Before the crew could act on that suggestion, Zammett called Pan Am Operations to report that they were heading back to New York and that the smoke was getting thicker. Operations asked if they needed equipment on arrival, to which Zammett told them they would make that decision in a few minutes.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/427/0*kVWO-HewLu4_2Rd5.png" /><figcaption>A B707 flight engineer station like the one used by Davis Melvin. (Daniel Berek)</figcaption></figure><p>At this time, flight 160 completed a 180-degree turn overhead Sherbrooke, Quebec, and was now proceeding back into the United States. First Officer Ritter signed off with Montreal and returned to Boston Center.</p><p>“##, it is getting heavy,” Zammett exclaimed.</p><p>“I think we better take it to Boston,” said Melvin.</p><p>“Yeah.”</p><p>“This # is getting thick back here,” Melvin repeated.</p><p>Diverting to Boston was faster than going to JFK, but it still wasn’t the closest airport. If the crew believed they were in an emergency, they would probably have diverted to Montreal. However, Boston was the nearest airport with a Pan Am maintenance facility, which suggested that they believed this was a problem that could be managed in the air and fixed on the ground.</p><p>As First Officer Ritter called up Pan Am Operations again, Captain Zammett said, “Tell ’em we wanna get down and head for Boston.”</p><p>“Yes sir, I think we’re gonna take this thing into Boston, this smoke is getting too thick,” Ritter reported to Operations.</p><p>Moments later, at time 09:11, all three crewmembers donned their oxygen masks, and then First Officer Ritter called for the descent checklist and requested descent from Boston center. The center then cleared them to descend from 31,000 to 19,000 feet.</p><p>“Do you guys want to get your goggles?” Zammett asked, referring to the smoke goggles, which they promptly put on.</p><p>Over the radio, Pan Am Operations asked, “Are you requesting equipment on arrival at Boston sir?” In this case “equipment” refers to the fire trucks.</p><p>“Do you want equipment on arrival at Boston?” Melvin asked. “Probably wouldn’t hurt, huh?”</p><p>“Stand by one — I don’t know, what did — how’s the smoke doing?” said Zammett.</p><p>“That #### is full back there,” said Melvin. He was probably looking into the crew rest area behind the cockpit, which was starting to fill up as smoke seeped through the barrier separating it from the main deck. Later tests proved that this barrier was somewhat permeable if the smoke was thick and/or if the curtain was poorly maintained.</p><p>“Better have the equipment,” Zammett concluded. In response, Melvin requested that Operations notify Boston to roll the fire trucks.</p><p>The pilots now began the descent checklist and grabbed their approach charts for Boston. First Officer Ritter also notified Boston of the nature of their emergency — although it was Boston who used the term “emergency,” not flight 160.</p><p>By 09:14, the transcript makes clear that the seriousness of the situation was increasing. At that time, Boston asked flight 160 to change to a new frequency, but Ritter requested to remain on their current frequency because “It’s too # hard to change.” Most likely he was unable to see the radio clearly enough due to the heavy smoke. This issue would have been even worse for Captain Zammett, whose smoke goggles didn’t fit properly over his spectacles, leaving gaps around the edges that allowed smoke inside. Modern smoke goggles don’t have this issue, but the goggles on the 707 were extremely primitive.</p><p>Flight 160 was now cleared direct to Boston, descending over Maine. With growing concern, Zammett asked the flight engineer, “How does it look in the back, Dave?”</p><p>“It’s full,” Melvin replied.</p><p>“Smoke detector showing much?”</p><p>“No, ah, it’s showing the same as it was,” said Melvin. “We’re somehow getting it up through the floor from down below and it’s going in the back I think.”</p><p>The pilots had no idea that inside the main deck, a raging fire was consuming a pallet of caustic chemicals located just aft of the wings.</p><p>At this point, Melvin suddenly realized that they were over their maximum landing weight. “We weigh 278 [thousand pounds] right now,” he pointed out.</p><p>“Okay, I think we’ll take it on in,” Zammett said, expressing his intention to land without delay despite their high weight.</p><p>“Just ease it on, it should be okay,” Melvin agreed.</p><p>Hopping on the radio, Zammett told Boston, “We’d like to get down as soon as possible so we can burn off some fuel rather than dump.” By flying at a lower altitude the rest of the way to Boston, they would burn fuel less efficiently, reducing the weight of the airplane at landing.</p><p>Meanwhile, Melvin continued to examine his panel for any sign of a problem, but there was nothing. “I can’t find a thing wrong back here,” he said. All systems were working normally.</p><p>“Okay, uh, maybe it’s in a package,” Zammett suggested.</p><p>“Could be,” said Melvin.</p><p>“Ah, you didn’t get in to open the door into the back section, did you?” Zammett asked. It seemed as though the pilots were on the brink of a realization. If they had been informed that there was hazmat on board, they would certainly have taken the possibility seriously. But instead Zammett said, “Ah, they’re supposed to be flame resistant or fire resistant anyhow, isn’t it?”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*P795aW85CUf5yp6fA-_0TA.png" /><figcaption>The checklist that the crew would have used if they had identified a main deck cargo fire. (Caledonian Airways via Classic Jetliners Forum)</figcaption></figure><p>The main deck cargo hold was what’s known as a Class E compartment. The primary method of controlling a fire in a Class E cargo compartment is to depressurize the aircraft to starve the fire of oxygen. However, the pilots of flight 160 never attempted to do this, and even if they had, it wouldn’t have worked, because the reaction between the nitric acid and sawdust was generating its own oxygen. This comment therefore represented a misunderstanding of the nature of both the fire and the 707 itself.</p><p>“Well, I — I looked back there — the smoke — there’s more smoke back there, but there’s none up here now,” said Melvin. As the heat of the fire cracked more nitric acid bottles, the amount of smoke would periodically increase, only to subside again temporarily before the next box of acid became involved, creating the fluctuations observed by the flight engineer. But, concluding his thoughts, Melvin again stated, “It must — it’s in the lower 41 someplace.”</p><p>“I think so,” Zammett agreed. It was an assumption that would seal their fate.</p><p>Over the next few minutes, Zammett continued to speak intermittently with air traffic control while discussing their plans with Melvin. They resolved to make a normal landing using the normal checklists, but Melvin also suggested that they advise the fire department of the suspected electrical fire. Zammett also decided that they would land on runway 33 because it was longer and the airplane was heavy. Later, Melvin informed Pan Am Operations that the fire was “either in the lower 41 or the forward cargo hold” but that “there isn’t too much [smoke] in the cockpit right now.”</p><p>Descending toward 2,000 feet, the pilots set up their instruments to capture the instrument landing system for runway 33 and completed the approach checklist. Zammett also instructed, “Ah throw the gear down please,” presumably to increase drag and use more fuel.</p><p>“Gear coming dow — “ First Officer Ritter started to say.</p><p>“Hold it, hold it,” Zammett interrupted. “Wait till I slow it down, we’ll tear the # doors off.” Due to their lengthy descent, their airspeed was too high to safely deploy the landing gear.</p><p>Meanwhile, Melvin was speaking with Operations. “Clipper 160, if you’re on the freq, would you advise us if the lower motor CB has been pulled, the blower motor CB,” Operations said, referring to the circuit breaker for the electronics equipment cooling blower. It’s not entirely clear why Operations would suggest this, given that the blower forces air into the lower 41 from the cockpit, and thus presumably was helping to keep the smoke out.</p><p>“I tried that, it didn’t make any difference,” Melvin replied.</p><p>Finishing up the checklist, Zammett commented, “I don’t smell that smoke as much now, there doesn’t seem to be as much, does it?”</p><p>“Ah, it doesn’t seem to be as much,” Melvin agreed. He then called the engineer’s check and approach check complete; all that remained was the landing checklist. But just moments later, at time 09:29, he suddenly said, “Ah, it’s definitely coming out of lower 41.”</p><p>“Still coming out, huh?” Zammett asked.</p><p>“Yeah,” said Melvin. “That’s worse, I don’t see — ”</p><p>In the background, Boston center reported that they were 45 miles from the field.</p><p>“It’s getting worse?” Zammett asked.</p><p>“Ah, I turned the equipment blower off and that made it worse,” Melvin explained. This was an expected result for the reasons I stated above. In fact, airflow testing later proved that the blower was practically the only thing keeping them alive. Without it, smoke would flow from the lower 41, through the pressure relief vent, and into the cockpit completely unimpeded.</p><p>“Okay, then if that’ll blow it out if you take the — keep it moving won’t it?” Zammett said.</p><p>“Yeah, I just pulled the breaker out again. I tried the CB to see if that’d do it but the — ” Melvin said. “Okay, it’s, uh — “</p><p>“All of a sudden it’s getting worse in here,” Zammett interrupted.</p><p>“It’s somewhere down in lower 41,” Melvin repeated once again. He then pushed the breaker back in to restart the blower.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*SkbrXzVM0cunqt5RQFFjiA.png" /><figcaption>The contradiction between the CVR transcript and the accident narrative. (NTSB, labels mine)</figcaption></figure><p>At this point a critical event occurred, but the NTSB report’s discussion of it contains a confusing contradiction. According to the narrative in the NTSB report, at approximately 09:31 Captain Zammett instructed the crew to “shut down everything you don’t need,” with quotations, implying a direct quote from the cockpit voice recording. However, the CVR transcript shows that at time 09:30:46, a person identified as the flight engineer, stated, “Tell ya what, turn the radar off, the dopplers off — anything ya don’t need, let’s shut ’em down.” At no point in the transcript does Captain Zammett issue an instruction similar to this, nor does anyone use the exact words quoted in the NTSB narrative. In fact, Zammett never even acknowledges Melvin’s desire to start turning off unnecessary systems.</p><p>It follows from this discrepancy that either the NTSB’s analysis of the accident or the CVR transcript misattributes and misquotes this crucial statement. Even after researching this accident in considerable depth, I’m still not sure who actually said it.</p><p>Whichever crewmember it was, they evidently wanted to shut down nonessential systems in an effort to isolate the source of the smoke. With no popped circuit breakers on his panel and no failure indications from any systems, yet having convinced himself that the smoke was coming from the avionics compartment, there was little left for the flight engineer to do except start turning things off just to see if it made any difference.</p><p>The first thing Melvin turned off was the weather radar, which was not needed since there was no significant weather in the area. “That’s off,” he announced. “Okay, it’s VFR, could I turn the ah, radio altimeter off?” The radio altimeter was most useful during instrument flight conditions; under visual flight rules, or VFR, he felt they wouldn’t need it.</p><p>Melvin never received a reply to these statements. At that time, First Officer Ritter was engaged in continuous conversation with Boston ATC, who told them to expect a visual approach to runway 33 left. The controller also asked if they were declaring an emergency, to which Ritter replied, “negative.” Ritter and Zammett then spent around 30 seconds discussing their landing weight.</p><p>After a awhile, Melvin interrupted to say, “Doesn’t seem to be getting any worse.”</p><p>“No, but I don’t think it’s getting any better, is it?” Zammett replied.</p><p>“No, it’s not getting any better,” Melvin agreed.</p><p>“It’s getting worse right now, you can see it blowing around here,” Ritter added.</p><p>Without further discussion, the pilots launched into the landing checklist. Boston ATC began vectoring them for a five mile final approach. Moments later, at 09:34:56, the cockpit voice recording ended mid-flight.</p><p>◊◊◊</p><p>By the time flight 160 was maneuvering for final approach, the fire in the main deck cargo area was burning ferociously both above and below the floor level, reaching temperatures in excess of 1,000˚F (538˚C). Evidence indicates that the fuselage skin adjacent to the fire started to melt while the plane was still in the air. The fire is also thought to have destroyed the wires that powered the cockpit voice recorder, resulting in its premature shutdown.</p><p>Thanks to various clues, some information is known about what happened during the final five minutes of the flight after the end of the CVR. For instance, based on the recovered positions of switches on the flight engineer’s panel, it was apparent that after turning off nonessential systems, flight engineer Melvin began working through the “Electrical smoke or fire” emergency checklist, pictured below. Since the origin of the smoke was not electrical in nature, none of the suggested solutions would have worked, and he would have progressed quite far down the checklist. One of these later steps was to set the “essential power” switch to “external.”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WrpX-j26YA1WdHFoD1nJeQ.png" /><figcaption>The procedure for electrical smoke or fire on the B707–320C. (Caledonian Airways via Classic Jetliners Forum)</figcaption></figure><p>The essential power switch affects the power source for all systems on the “essential bus,” which distributes electrical power only to the most crucial systems on the airplane — as the name implies. To get this far in the checklist, you have to try turning off damn near everything else first, without success.</p><p>Setting the “essential power” switch to “external” will configure the essential bus to distribute power from an external power source when the aircraft is on the ground. In the air, since there is no external power source, this position cuts power to the bus and all systems on it. Those systems would have included the captain’s instrument panel, the captain’s VHF radio, the cockpit voice recorder, the transponder, the cockpit interphone system, and the yaw damper, among other items. However, by this point the CVR had already failed.</p><p>After the accident, the essential power switch was indeed found set to “external,” indicating that Melvin must have cut power to essential systems at some point after the end of the CVR recording. It’s not known whether the crew followed the advice at the start of the checklist, which advises the pilots to “prepare for manual trim and loss of rudder power A.P. and yaw damper.” In fact, the NTSB suspected that such preparations were not made.</p><p>As flight 160 aligned with the runway and commenced its final approach, the controller asked, “Clipper 160, advise anytime you have airport in sight.” But there was no reply from the aircraft. Seconds later, its transponder disappeared from the controller’s radar screens, although the airplane was visible in the distance, clearly still airborne. The loss of radar and radio contact were actually caused by the loss of the №1 VHF radio and transponder when the flight engineer cut power to the essential bus.</p><p>If the pilots were properly preparing for each step, they would have moved the VHF radio selector switch to №2, allowing both pilots to use the still-powered alternate VHF radio. However, the loss of radio contact, and the crew’s failure to reestablish it, suggests that the flight engineer cut essential power without ensuring that the other crewmembers understood what would happen.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*F4iCErgld4mE2z_xnAPYaQ.png" /><figcaption>The smoke evacuation checklist for the B707–320C. (Caledonian Airways via Classic Jetliners Forum)</figcaption></figure><p>This breakdown in crew communication might have taken place amid rapidly deteriorating conditions inside the cockpit. Witnesses on the ground reported that during the last phase of the approach, smoke was pouring through the open left cockpit sliding window. Thick smoke deposits were later found around this window, testifying to extreme conditions inside. Most likely, amid thickening smoke, the pilots opened the window in accordance with the final, most desperate solution prescribed by the cockpit smoke evacuation checklist. Unfortunately, the checklist assumed, first of all, that the smoke source was inside the cockpit; and second, that smoke was not being generated continuously. Neither of those was true in this case, and in fact, opening the cockpit window while a fire is actively burning inside the main deck cargo area was experimentally demonstrated to increase the rate of smoke intrusion into the cockpit. Considering the captain’s poorly fitting smoke goggles, and the fact that cutting essential power disabled the interphone that the pilots were using to communicate through their oxygen masks, their ability to fly the airplane would have been substantially compromised from that point onward.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/850/0*e5Vxurzm6tuN5ma3.png" /><figcaption>The sequence of motions involved in Dutch roll. (Roberto Merino-Martinez)</figcaption></figure><p>But in the end, the real killer wasn’t the smoke: it was the inoperative yaw damper. And to explain why, we need to go down yet another, no less fascinating rabbit hole.</p><p>The yaw damper is a device that automatically makes constant, small rudder inputs in order to prevent unwanted excursions on the yaw axis — that is, nose left and nose right. All large swept wing jets have a yaw damper to improve their directional stability, and in fact the 707 was one of the first aircraft to incorporate one.</p><p>Without a yaw damper, swept wing jets tend to fall into a dynamic cycle known as “Dutch roll.” Basically, as the plane starts to yaw in a particular direction, let’s say nose right, then the left wing moves into a position where the airflow over its surface is more direct, resulting in increased lift. At the same time, the right wing falls back into a less advantageous position, resulting in decreased lift. Then, with more lift on the left and less on the right, the airplane starts to roll to the right. So in other words, a yaw tends to turn into a roll in the same direction. But as the yaw, or sideslip angle, increases, the aerodynamic force against the big, flat side of the vertical stabilizer also increases, until eventually that force causes the entire aircraft to weathercock back the other way. The yaw angle then passes back through neutral and into the opposite position, which in our example would be nose left. Correspondingly, the direction of bank reverses from right wing down to left wing down. This cycle then repeats, over and over and over — and that’s what we call Dutch roll.</p><p>Dutch roll is typically excited by a sudden yawing force, such as a lateral wind gust or an accidental rudder input. It’s not inherently dangerous on most aircraft but it is extremely uncomfortable for the occupants, so the yaw damper works constantly in the background to ensure that it doesn’t happen. And even if it does, the pilot can recover simply by holding the wings level.</p><p>Even without the yaw damper, modern aircraft are designed so that their inherent Dutch roll characteristics are either stable (the amplitude of each swing is smaller than the one before it) or neutral (the amplitude of each swing is equal to the one before it). This is as opposed to an aircraft with unstable Dutch roll characteristics, in which each swing is larger than the one before it, which will eventually result in either loss of control or in-flight breakup of the aircraft if not corrected by the pilot or the yaw damper.</p><p>Because the 707 was one of the first jet airliners ever designed, its engineers were not as successful at damping its Dutch roll characteristics as they are today. Early 707s were inherently unstable in Dutch roll without the yaw damper under all conditions. In later versions, this tendency was reduced, but some edge cases remained. Dutch roll on any aircraft is worse at low speed and high angles of attack with the flaps extended simply because these factors reduce controllability on the roll axis (i.e., larger inputs on the flight controls are required to produce the same roll response). This tendency is made even worse if the pilots have extended the speed brakes to reduce lift and slow the plane for landing.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Uq64-yDrp3Rt4UWzNg0FXQ.png" /><figcaption>Information about Dutch roll stability, from “Handling the Big Jets” by David P. Davies, 1971.</figcaption></figure><p>According to the NTSB, flight testing has demonstrated that with the flaps fully extended to 40 degrees, the speed brakes extended, and the yaw damper inoperative, the Boeing 707’s Dutch roll characteristics become so unstable that “lateral control capability may be extremely limited, if not impossible.” In other words, the roll inputs required to recover from Dutch roll in that configuration equal or exceed the limits of the pilot’s roll authority.</p><p>Before Flight Engineer Melvin started turning off critical systems, the pilots had not successfully stabilized the airplane for landing. In fact, when they made the final turn onto their truncated final approach, the aircraft was too high and was traveling too fast, which prompted the pilots to extend the flaps to 40 degrees and deploy the speed brakes in an attempt to slow down. Subsequently, when Melvin cut power to the essential bus, the yaw damper was disabled, placing the airplane into a configuration in which it was uncontrollable. If this matter had been discussed with the pilots beforehand, it’s doubtful that Melvin would have proceeded with cutting power, so it’s almost certain that Captain Zammett didn’t know that this was about to happen.</p><p>On the ground, witnesses watched with growing alarm as the aircraft started to sway from side to side, back and forth, over and over, each swing growing larger and wilder than the one before. The aircraft was experiencing unstable Dutch roll, and although the pilots no doubt fought to halt the exaggerated gyrations, the only way to save the plane was to turn the yaw damper back on. Unfortunately, amid the chaos, the flight engineer never managed to do so.</p><p>Moments later, at approximately time 09:40, the airplane entered a bank that was too steep to sustain; the wings lost lift, the nose fell through, and the 707 dived toward the ground. Within a few seconds it was all over. Pan Am flight 160 spun and impacted the ground next to the threshold of runway 33, traveling almost perpendicular to the runway, in a steep nose down attitude with nearly 90 degrees of left bank. The fuel tanks exploded on impact, sending a huge fireball curling over Logan Airport as burning debris careened across the threshold, over the seawall, and into Boston harbor, setting fire to the approach lighting pier. Firefighters rushed to the scene and quickly extinguished the fire, but their rescue efforts were fruitless; all three crewmembers died on impact.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/612/0*EGWB2VEjTSpGG7BM" /><figcaption>One of three photos I was able to conclusively identify as showing the aftermath of flight 160. When searching for photos of the crash, most of the results are from Delta flight 723, which also crashed at the threshold of a runway at Boston Logan Airport in 1973. (Boston Globe via Getty Images)</figcaption></figure><p>The National Transportation Safety Board’s analysis of the events leading up to the crash of flight 160 focused on three principal areas: the design of the aircraft; the actions of the crew; and the packaging and loading of the hazmat.</p><p>Although readers’ attention with regard to aircraft design is probably drawn toward the instability of the 707 in Dutch roll, this matter only received a single line in the NTSB report, and I had to do considerable outside research to confirm what the actual problem was. Instead, most of the NTSB’s focus was directed at the means available to exclude smoke from the cockpit. After all, the smoke in the cockpit was the motivating factor that led the crew to start searching for increasingly dangerous solutions. It also probably compromised the crew’s ability to fly the airplane safely during the final minutes due to lack of visibility.</p><p>Under federal regulations at the time, and still today, a class E cargo compartment, such as the main deck of a purpose-built freighter, must have <em>“means to exclude hazardous quantities of smoke, flames, or noxious gases from the flight compartment.”</em> If that regulation sounds familiar, then you’re probably thinking of <a href="https://admiralcloudberg.medium.com/alone-in-the-inferno-the-crash-of-ups-airlines-flight-6-507d13f3e481">my previous article on UPS Airlines flight 6.</a></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1023/0*v6hRCCb-kR13Yf7j.jpg" /><figcaption>N571UP, the aircraft involved in the UPS 6 accident in 2010. (Konstantin von Wedelstaedt)</figcaption></figure><p>To recap that story, in 2010 a Boeing 747 freighter experienced a fire in the main cargo deck, a class E compartment, due to thermal runaway of improperly packaged lithium batteries. The 747’s air conditioning packs were supposed to maintain positive pressure between the cockpit and the main deck so as to exclude smoke from the crew area. However, the procedure for extinguishing a fire in the main deck was to depressurize the hold, which involved turning off two of the three air conditioning packs. Not only did this fail to extinguish the fire, which was fueled by a chemical reaction that didn’t need oxygen to sustain itself, it also left the crew with no smoke protection after the third and final air conditioning pack suffered an unrelated malfunction. The cockpit subsequently filled with smoke, leading to the incapacitation of the captain. The first officer attempted to land the plane by himself but he was unsuccessful due to being unable to see.</p><p>In that accident, the United Arab Emirates General Civil Aviation Authority, which led the investigation, determined that the concept of a class E cargo compartment was potentially flawed, in that depressurizing the compartment required maintaining a high altitude to starve the fire of oxygen, which was in conflict with the need to land immediately in the event of a fire. They also found that depressurizing the hold was ineffective against fires involving hazardous materials and possibly ineffective against normal fires as well. Furthermore, the smoke detection systems wouldn’t detect the fire early enough to intervene before it became catastrophic if the fire started inside a container or a pallet with a rain cover. Investigators also expressed concern that the design of the 747’s emergency checklists did not provide adequate assurance that smoke would not enter the crew area.</p><p>If all of this sounds like it should apply to Pan Am flight 160 as well, that’s because it does. The procedure for a fire in the class E compartment on the 707 was also to depressurize and climb to a high altitude, which would have failed to extinguish the fire on flight 160 because nitric acid is an oxidizer that produces its own oxygen. This issue was tangentially addressed in the NTSB report, although the report didn’t discuss the inherent contradiction between this directive and the need to land immediately, even though investigators noted that the pilots should have landed immediately if they knew there was hazmat on board. Additionally, as in UPS 6, the smoke detector failed to provide timely warning of the fire, contributing to the pilots’ erroneous assumption about the location of the blaze.</p><p>Once the fire was underway, the smoke barrier between the main deck and the crew area generally prevented smoke from entering the cockpit in a wholesale manner, but based on the pilots’ statements, considerable smoke nevertheless made it into the cockpit by traveling down the smoke chute from the main deck, into the lower 41 compartment, and then up into the cockpit via the pressure relief vent. The NTSB and the FAA were concerned that this had happened even though the pilots followed the smoke evacuation checklist by increasing the cabin altitude to 10,000 feet, opening the outflow valves, and turning the bleeds to max. The exact reason why these actions failed to prevent smoke intrusion wasn’t determined, but investigators believed that the existence of an alternate airflow path into the cockpit via the lower 41 caused the 707 to fall short of the regulatory requirement for “means to exclude hazardous quantities of smoke… from the flight compartment.”</p><p>After the accident, testing also showed that thick smoke would rapidly enter the cockpit via this route if the equipment cooling blower was turned off. This didn’t cause the smoke intrusion on flight 160 even though the flight engineer turned the blower off twice, simply because he turned it back on right away. But the FAA was concerned that if an electrical problem were to occur, or the blower malfunctioned, then there would be nothing to stop smoke from freely entering the cockpit. Doesn’t that sound a lot like what happened on UPS flight 6, with its malfunctioning air conditioning pack?</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-7cRa7IqYWbf7RIDtBug4A.png" /><figcaption>The first page of the FAA’s letter to Boeing about Pan Am flight 160. (NTSB)</figcaption></figure><p>In 1974, the FAA laid out some of these concerns in a letter addressed to Boeing, which cited the Pan Am flight 160 CVR transcript to argue that the pilots followed the smoke evacuation procedure but that the procedure was ineffective. However, Boeing replied that it had conducted smoke generation and airflow tests in May 1974 and found that the procedures adequately excluded smoke. Even when a continuous smoke source was placed in the main deck, Boeing reported that smoke didn’t move from the lower 41 into the cockpit. Boeing also argued that the CVR didn’t contain sufficient evidence to conclude that the pilots had followed the procedures correctly.</p><p>However, in their reply to the FAA, Boeing also wrote, <em>“If the procedure is followed, a continuous source of smoke will not exist as the fire will be smothered, except in the rare case where a hazardous material is carried which is packaged and handled such that it is released, generates heat, and provides its own oxygen.”</em> So in other words, exactly what happened on Pan Am flight 160 and UPS flight 6 — and on several other notable flights, including but certainly not limited to <a href="https://admiralcloudberg.medium.com/value-for-money-the-crash-of-valujet-flight-592-762db479ca7d">ValuJet flight 592</a> (1996, 109 killed), American Airlines flight 132 (1988, 13 seriously injured), and Asiana Airlines flight 991 (2011, 2 killed). All of these accidents and incidents involved fires caused by hazardous materials that generated oxygen as a byproduct, allowing them to grow and expand inside a cargo compartment where the active means of fire suppression was oxygen starvation, including compartments designated both class E and the now-defunct class D. So while it’s true that such accidents are rare, they aren’t really as rare as Boeing wanted to believe. Boeing also didn’t explore the possibility that depressurization is not fully effective at stopping non-self-oxygenating fires, which we know today to be true.</p><p>One of the big issues with Boeing’s mindset was that checklists related to smoke clearance assumed the fire was already extinguished, which could cause the pilots to take potentially dangerous actions if smoke was still being generated. In fact, there are many reasons why a crew might not be able to extinguish a fire, including not only the reasons discussed above, but also other reasons, such as incorrect identification of its source (e.g. Pan Am flight 160); a fire in an inaccessible location (e.g. <a href="https://admiralcloudberg.medium.com/candles-in-the-wind-the-crash-of-swissair-flight-111-88d90b63c930">Swissair flight 111</a>, <a href="https://admiralcloudberg.medium.com/a-song-of-smoke-and-fire-the-tragedy-of-air-canada-flight-797-7ea7923e76d8">Air Canada flight 797</a>); or a fire whose intensity exceeds the capabilities of the available extinguishing equipment (e.g. <a href="https://medium.com/@admiralcloudberg/fall-of-the-helderberg-the-crash-of-south-african-airways-flight-295-ef6261a01b46">South African Airways flight 295</a>). In any of these situations, the crew might — and in several of the above cases, actually did — attempt to evacuate smoke while the fire was still burning.</p><p>If the flight crew reaches the final step on the smoke evacuation checklist, they will be advised to open a window in flight. On the 707, this was the cockpit sliding window; on UPS flight 6, this was a specially designed smoke shutter in the ceiling. But already in 1973, it had been demonstrated that opening a window in the cockpit while the fire is still burning will create an airflow path that draws more smoke into the cockpit. Despite this, the checklist didn’t warn the crew to apply the procedure only after extinguishing the fire. In fact, this warning also wasn’t included in the smoke and fumes removal checklist used by the ill-fated UPS crew 37 years later, and consequently that crew also unknowingly worsened the smoke intrusion by opening the smoke shutter. It’s unclear that either accident would have been prevented if the crew had kept the windows closed, but opening them certainly didn’t help.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/612/0*lH3epfYJ7YFgF5R9" /><figcaption>Fire trucks at the scene of the crash of flight 160. (Boston Globe via Getty Images)</figcaption></figure><p>In its final report, the NTSB recommended that the design of the 707 be changed to exclude an airflow path that could cause hazardous quantities of smoke to enter the cockpit; that operators be provided with supporting data to create more effective smoke evacuation procedures; and that the FAA evaluate whether certification tests adequately reflected the range of situations in which flight crews would apply the smoke evacuation procedures. Unfortunately, the NTSB did not specifically recommend that Boeing and the FAA reevaluate the checklist instruction to open a window, or the assumption that it’s possible to extinguish a fire in a class E cargo compartment by depressurizing the airplane.</p><p>The NTSB also recommended that flight crews receive more training on how to identify the source of smoke or fire, and that flight crews be trained to land immediately following any in-flight occurrence that they believe to be related to hazmat on board the aircraft. But while these recommendations seemed sensible at the time, modern guidance for flight crews is to land immediately whenever smoke or fire is present, regardless of what the pilots believe is the source. In several accidents during the 1970s and 1980s, including flight 160, flight crews facing in-flight fires did not land at the nearest available airport because they falsely believed that the fire was in a location that did not directly threaten the safety of the airplane. Encouraging identification of the source of unknown smoke before making a decision about whether to land immediately was an industry practice that cost lives. Identifying the source is still important, but it must come after the decision to land.</p><p>In my opinion, Pan Am flight 160 represented a missed opportunity to reevaluate the assumption that flight crew identification of the smoke source was an appropriate or reliable means by which to judge the severity of a fire emergency.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*Z4VF-Kd3irHBncdC.jpg" /><figcaption>The remains of flight 160’s burnt-out fuselage. (FastStone/Vintage Image Photos via eBay)</figcaption></figure><p>The second major issue that contributed to the accident, after aircraft design, was crew coordination. Most significantly, the pilots might have been able to land the plane in one piece if the flight engineer had not cut essential electrical power, disabling the yaw damper. The flight engineer’s decision to follow the provisions of the “electrical fire or smoke” checklist was not coordinated with the pilots and the crew apparently did not discuss or prepare for the effects of shutting off essential power. Modern crew resource management training emphasizes the role of each crewmember in maintaining group awareness through the use of callouts and collective decision-making. But in 1973, this training did not yet exist, nor did the investigators conceive of its future importance, and no recommendations related to the issue were made.</p><p>The misidentification of the smoke source also highlights the dangers of confirmation bias. At several points during the emergency, the flight crew considered the possibility that the fire might be on the main deck, and even named multiple indications that the fire was not in the avionics compartment, including the absence of any popped circuit breakers or equipment malfunction warning lights. And yet, despite these doubts, no crewmember ever went to the main deck to check whether the cargo was the source of the fire. Instead, they repeatedly rationalized their initial incorrect assumption despite growing evidence that it was wrong. This is a natural human tendency that has to be actively resisted using error entrapment and mitigation strategies — strategies that are taught today, but were not taught in 1973. If the crew had been taught how to constantly reevaluate their mental models of the situation based on the raw indications that they were receiving, they might have decided to check for a fire on the main deck — and if they had done that, the flight engineer wouldn’t have started turning off electrical equipment, and the crash might not have happened.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fov9KUN9rm6iEvSHBq3jZw.png" /><figcaption>NTSB Wreckage Distribution Chart</figcaption></figure><p>The third major causal factor was the failure by multiple companies to ensure that the nitric acid shipment was properly packaged and loaded. Based on my analysis of the information in the NTSB report, Allied Chemicals most likely packaged the nitric acid bottles with flammable sawdust cushioning; Santini Brothers, entrusted by NSC to repackage the acid for air transport, did not replace the sawdust or affix the required warning labels; and Pan Am’s cargo loaders turned the boxes of hazmat sideways in order to fit them into the aircraft. Each of these mistakes contributed directly to the eventual leakage and fire that brought down the plane.</p><p>Given the number of people and companies involved in this chain of errors, it was impossible to assign blame to any single person or entity. Legally speaking, regulations at the time placed responsibility for proper hazmat packaging onto the shipper, who in this case was NSC, but NSC had no operational control of the shipment at any point before it was loaded onto the aircraft. In fact, NSC was not involved in the shipping business and had no means whatsoever to ensure proper handling of the materials. Instead, the nitric acid was packaged and transported by employees of ACC, Santini, P. Calahan Inc., and Pan Am’s contract cargo agent Interamerican. Among the people at these companies who directly handled the nitric acid, the only person with any recent or formal hazmat training was the Santini office manager, and even he accepted Lyon’s assertion that sawdust was a safe cushioning material for an oxidizing chemical.</p><p>Part of the problem was that regulations surrounding hazmat handling, packaging, and transport are extremely complex with detailed requirements for each individual chemical. It was difficult even for trained personnel to become familiar with all the requirements, and the US Department of Transport had not published any single document containing all of the relevant regulations. As a result, even in cases where personnel received hazmat training, it wasn’t particularly easy to access the rules that they were expected to follow.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*GChCJhuXYaTH6Rctfk3cRA.png" /><figcaption>The Hazardous Materials Table from 49 CFR § 172.101. Damn near every chemical you can imagine is in here. I actually had a lot of fun scrolling through to see what chemicals are completely forbidden to transport by air.</figcaption></figure><p>Today, FAA and DOT hazmat rules can be found on the internet by consulting the US government’s electronic code of federal regulations, Title 49, Subtitle B, Chapter I, Subchapter C, Parts 171–180. As an experiment, I — a complete amateur with no hazmat training and no previous experience with these regulations — decided to see whether I could figure out how to transport nitric acid by air in 2025. In the end, it took several hours for me to learn how to navigate the system of tables and codes linking each part of Subchapter C, but I was eventually able to determine that nitric acid with a concentration below 70% can be carried on cargo aircraft in bottles not larger than 2.5 L; the bottles must be glass, earthenware, or plastic with a metal overpackage; for bulk carriage, the bottles must be placed into an aluminum or steel canister; and the canisters must be placed into wood or metal boxes of certain federal specifications. I wasn’t able to find any requirements for a cushioning material that applied to nitric acid, however I did find cushioning material standards with codes applying to certain other chemicals. I’m still not entirely sure whether regulations no longer require noncombustible cushioning material, or if I just missed something due to inexperience. The regulation specifying the cushioning material that was quoted in the NTSB report, Part 173.268, no longer exists. So if I were to follow the regulations I found to the letter — not that I would ever do this, seeing as I’m not qualified to ship acid — then I would have put the nitric acid into 2.5 L glass bottles, put the bottles into metal canisters, and then put the bottles into DOT specification boxes with labels reading “corrosive” and “oxidizer.” I didn’t find where the regulations require “this end up” labels, but I’m sure they do somewhere.</p><p>Using this tool, and assuming I had access to the proper containers, I would have packaged the nitric acid more safely than it was packaged for Pan Am flight 160. Due to my lack of training and unfamiliarity with the system, I would have made some mistakes, but probably not as many. So the conclusion I’ve drawn from this exercise is that US hazmat regulations are vastly more user-friendly today than they were in 1973, even though they remain extraordinarily complicated. Furthermore, the availability of hazmat training is much more widespread than it was in 1973, and most employees involved in handling hazmat today are required to receive formal training.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uJGW4WqO4eK6ZWSN_A6ivQ.png" /><figcaption>The first page from the NTSB’s letter to the FAA containing recommendations related to hazmat. (NTSB)</figcaption></figure><p>Although a lot of this improvement has to do with the miraculous invention of the internet, awareness and enforcement of hazmat regulations also improved as a result of several NTSB recommendations stemming from Pan Am flight 160. These recommendations included the following:</p><p>- The FAA should make the dispatcher directly responsible for notifying the captain of the presence of hazardous materials in the cargo.</p><p>- The FAA should prohibit air carriers from relying on the shipper’s word as <em>prima facie</em> evidence of the shipment’s compliance with hazmat regulations, and require air carriers to implement a system for inspecting hazmat shipments at the receiving point prior to loading them onto an aircraft.</p><p>- The FAA should create a system for air carriers to notify the FAA if a shipment is found not to be in compliance with hazmat regulations, and require the use of this system.</p><p>- The FAA should conduct a one-time inspection of each air carrier’s cargo receiving, palletizing, inspecting, and loading procedures to ensure regulatory compliance.</p><p>- The FAA and DOT should develop a checklist that personnel can use to determine whether a hazmat shipment meets federal regulations.</p><p>- The FAA should disseminate information about the requirements for air transport of hazmat directly to air carriers’ sales’ representatives who accept bookings from shippers.</p><p>The FAA ultimately implemented almost all of these recommendations. In addition to improving access to hazmat information, these changes also motivated air carriers to inspect and handle hazmat more cautiously, as regulations now hold carriers partly responsible for the safe packaging of hazmat carried aboard their aircraft.</p><p>And most importantly, in 1975, the US Congress passed the Hazardous Materials Transportation Act, which greatly expanded the authority of the Department of Transportation to regulate the packaging, handling, labeling, and transport of hazardous materials in all modes; and to enforce those regulations through inspections, investigations, civil penalties, and criminal penalties. The act specifically cited the crash of Pan Am flight 160 as a major impetus behind its passage, and the newly empowered DOT went on to overhaul the hazmat transportation regulation process as well as the regulations themselves.</p><p>◊◊◊</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*1MRGJlA6INrprgaW" /><figcaption>N458PA’s sister ship, N457PA, takes off from Heathrow. (Ad Vercruijsse)</figcaption></figure><p>Looking back from more than a half century later, the crash of Pan Am flight 160 was at once a product of its time and a glimpse into the future. It represented an opportunity to learn a wide variety of lessons, some of which were learned to great effect, while others were not, and thus returned to kill again. Some of the causes of the accident might leave a modern reader horrified to discover how things were done in 1973, while others might strike aviation safety experts as surprisingly relevant to the present day. That makes flight 160 both a story of historical interest and a good case study for how human factors, information presentation, and procedural design can turn a hazard into an emergency and an emergency into a fatal accident.</p><p>Unfortunately, it was a case study without a happy ending, as the crew navigated their burning airplane to the very threshold of the runway, only to be undone by the consequences of an assumption they had made over half an hour earlier. It was the last assumption in a long string of them, from the checklist that assumed the fire had been put out before opening a window, to the logistics employee who assumed that nitric acid could be cushioned with sawdust because it wasn’t flammable. The outcome was a tragic example of why assumptions are dangerous, and why trust must be paired with verification. Neither flying nor hazmat is inherently safe, and both are as safe as they are today because everyone involved has worked hard to make them so, rather than assuming that everything is fine, or that someone else will take care of it. Because safety will never be someone else’s problem — it always has been and always will be everyone’s problem.</p><p>_______________________________________________________________</p><p><em>Note to readers: Because the NTSB report on this crash was unusually vague, my narrative of the accident includes personal deductions about what was meant by certain phrases and concepts and who performed certain actions. I reached best-guess conclusions in many of these areas after consulting with others and examining numerous documents, but my logic is not necessarily unimpeachable. If you know something about this case, or any of the people, companies, airplanes, or systems involved, and you think you can add to or clarify the information in this article, please shoot me an email. Thank you!</em></p><p>_______________________________________________________________</p><p><em>Don’t forget to listen to Controlled Pod Into Terrain, my podcast (with slides!), where I discuss aerospace disasters with my cohosts Ariadne and J! </em><a href="https://www.youtube.com/@ControlledPodIntoTerrain"><em>Check out our channel here</em></a><em>, and listen to </em><a href="https://www.youtube.com/watch?v=-i3dZNFDk84"><em>our latest episode about a titanic battle between a BAC 1–11 and some wind.</em></a><em> Alternatively, download audio-only versions via </em><a href="https://rss.com/podcasts/cpit/"><em>RSS.com</em></a><em>, or look us up on Spotify!</em></p><p>_______________________________________________________________</p><p><a href="https://www.reddit.com/r/CatastrophicFailure/comments/1jln4aw/1973_the_crash_of_pan_am_flight_160_a_boeing_707/">Join the discussion of this article on Reddit</a></p><p><a href="https://www.patreon.com/Admiral_Cloudberg">Support me on Patreon</a> (Note: I do not earn money from views on Medium!)</p><p><a href="https://bsky.app/profile/kyracloudy.bsky.social">Follow me on Bluesky</a></p><p>Visit <a href="https://www.reddit.com/r/AdmiralCloudberg/">r/admiralcloudberg</a> to read and discuss over 260 similar articles</p><p><a href="https://docs.google.com/document/d/16O3Q3ElPWIJAHIv710Q59ykZO7T2EqiPO6sWWz7VS8w/edit?usp=sharing"><strong>Bibliography</strong></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=bed699b6b8b2" width="1" height="1" alt="">]]></content:encoded>
        </item>
    </channel>
</rss>